Pull to refresh
Logo
Chess.com data leak exposes millions of accounts; evidence points to scraping

Chess.com data leak exposes millions of accounts; evidence points to scraping

Force in Play

Researchers verified records for 7.3 million users are genuine, but no passwords or payment data were in the file

Today: 7.3 million-record file posted free on leak forums

Overview

Updated 1 hour ago

A 15.5-gigabyte file holding records for 7.3 million Chess.com accounts surfaced on two data-leak forums this week, free of charge. It contains email addresses, usernames, real names, countries, chess ratings, and subscription tiers.

Researchers who decoded the data say it is genuine and recent, but the evidence points to automated scraping rather than a server intrusion. No passwords or payment data are in the file, which limits the immediate damage. Still, three-quarters of records carry an email address — paired with personal details, that is enough to build convincing phishing messages.

This is the third reported scraping incident involving Chess.com in roughly three years and the largest by far, about nine times the size of the 2023 scrape that exposed 828,000 accounts. The company had not confirmed the incident as of publication.

Why it matters

If your email was in the file, scammers have your username, rating, and country to build phishing messages that look like official Chess.com notices.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

7.3M
User records in leaked file
15.5 GB dataset posted free to two leak forums and Telegram.
4.6M
Unique email addresses exposed
Roughly three-quarters of records include an email address.
7.4%
Duplicate records in file
Same accounts appear twice across daily batches — a signature of scraping, not a database export.
100%
UUID timestamp verification rate
Decoded version-1 UUID timestamps matched registration dates across 200,000 samples.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

November 2023 September 2026

3 events Latest: Today
  1. 7.3 million-record file posted free on leak forums

    Today Data leak

    V0idix releases a 15.5 GB dataset to two forums and Telegram; three-quarters of records carry an email address.

  2. First Chess.com scrape publishes 828,000 records

    Data leak

    Threat actor publishes 828,000 records; Chess.com denies a breach.

Scenarios

1

Chess.com says it's scraping, offers no remediation

Likely Resolves by Oct 31, 2026

Discussed by: Ransomnews, Hackread, and the company's own 2023 precedent

Chess.com issues a statement acknowledging the dataset came from scraping — likely via the find-friends contact-matching feature, as in 2023 — and reiterates that its servers were never compromised. Given the company's past response and its refusal to add two-factor authentication, minimal security changes are expected. The most concrete action would be rate-limiting the find-friends endpoint.

2

Data protection regulator opens inquiry into Chess.com

Possible Resolves by Q2 2027

Discussed by: Privacy advocates and commentators citing GDPR obligations; the LinkedIn 2021 scrape precedent

Chess.com has users worldwide, including in the EU and UK, where exposing 4.6 million email addresses without adequate safeguards can trigger data-protection scrutiny. The LinkedIn 2021 scrape led the Irish Data Protection Commission to investigate and eventually fine the company €310 million in 2024. A similar path would start with a regulator announcing a formal inquiry into how Chess.com collects, exposes, or retains user data.

3

Fourth and larger Chess.com scrape surfaces

Possible Resolves by End of 2027

Discussed by: The incident track record (828K → 476K → 7.3M) and Hackread's note that email and marketing fields should not be public

Each scrape has been roughly an order of magnitude larger than the last, and the technique — abusing contact-matching or an exposed interface — has gone unaddressed for three years. If Chess.com does not lock down the underlying feature, another, larger collection is plausible. Hackread noted that internal Google Ad Manager audience labels in the file should not be publicly accessible, suggesting an exposed internal interface the scraper found.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

April 2021

Facebook phone-number scrape (April 2021)

A dataset of 533 million Facebook users' phone numbers, names, and locations circulated publicly. Facebook said the data was collected by abusing a contact-importing feature, not by a server breach.

Then

The dataset spread across forums for months; Facebook added some rate limits to contact matching.

Now

The incident became a standard reference point for scraping abuse of contact-matching features.

Why this matters now

The mechanism — a contact-matching feature resolving external inputs against accounts — is nearly identical to Chess.com's find-friends method.

April 2021

LinkedIn scrape (April 2021)

A dataset of 500 million LinkedIn user profiles was listed for sale on a hacking forum. LinkedIn confirmed it came from scraping publicly visible profile information.

Then

LinkedIn said no account compromise occurred and no private message data was exposed.

Now

The Irish Data Protection Commission later fined LinkedIn €310 million in 2024 for GDPR violations, part of which grew from the scrape investigations.

Why this matters now

Shows that a data exposure caused by scraping can still draw regulatory action, even without a technical breach.

November 2023

Chess.com first scrape (November 2023)

A threat actor published 828,000 Chess.com account records with a field structure nearly identical to the 2026 file. Chess.com said the data was pulled by abusing the find-friends feature, which resolves email addresses against accounts.

Then

Chess.com denied a breach and made no major security changes.

Now

The same technique reappeared at roughly nine times the scale in 2026.

Why this matters now

Direct precedent at the same company: the scrape method was known and unaddressed.

Sources

(5)