Chess.com data leak exposes 7.3 million players

The reported leak involves 7,337,396 Chess.com account records, distributed as a 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table. The database reportedly contains 4,656,791 email addresses, along with usernames, account IDs/UUIDs, first and last names, countries, locations, locales, chess titles, ratings, skill levels, premium/subscription status, verification and activation flags, member-since dates, and last-login timestamps. Some records also contain avatar links and internal Google Ad Manager audience-segmentation tags, including coaching experiments, trial eligibility, lapsed-user groups, and rating-based targeting. No passwords, password hashes, or payment information were found, meaning the leaked data alone does not appear sufficient to directly log into affected accounts.

Evidence suggests the data is genuine and was likely obtained through large-scale scraping rather than a conventional server breach. Researchers found that version-1 account UUIDs contained embedded timestamps matching account-registration dates across a sample of 200,000 records. The records were collected in daily batches over nine consecutive days, and approximately 7.4% appeared more than once, consistent with repeated automated collection. The technique also appears similar to Chess.com’s 2023 incidents, when approximately 828,000 records and then another 476,000 records were scraped, reportedly by abusing the platform’s find-friends functionality. However, the presence of internal advertising-audience data raises questions about whether the latest collection involved an authenticated or internal-facing endpoint rather than only publicly accessible information.

Although the absence of passwords and payment data significantly limits the immediate account-takeover risk, the leaked information still provides valuable material for phishing and social engineering. A scammer could use a real email address, name, country, chess rating, and subscription status to create a convincing fake Chess.com message about a tournament invitation, membership renewal, account-security alert, or fair-play issue. Chess.com users should therefore treat unexpected emails or messages referencing their accounts with extra suspicion and avoid clicking login links; instead, they should go directly to Chess.com through their browser or app.

Read more about it here.

Leave a Reply

Your email address will not be published. Required fields are marked *