← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Chess.com User Data Leak Exposes 7.3M Records, Likely Due to Scraping

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 7.3 million Chess.com user records leaked on data-leak forums.
  • Data includes emails, usernames, real names, chess ratings, and internal marketing tags.
  • No passwords or payment data were exposed.
  • Evidence points to data scraping over nine days, not a system breach.
  • Data authenticity confirmed by matching UUID timestamps with registration dates.

Millions of Chess.com User Records Leaked

A 15.5 GB file containing 7,337,395 Chess.com user records has been distributed on data-leak forums. The file, offered at no cost, includes a wide range of user information such as email addresses, usernames, user IDs, real names, countries, chess titles, skill levels, premium status, and various rating data. Approximately three-quarters of the records contain an email address.

Internal Marketing Data Included

Notably, the leaked data also contains internal Google Ad Manager audience segments, such as 'coach-nudge experiment groups' and 'lapsed-user cohorts'. These marketing-stack fields are not typically available through Chess.com's public API, suggesting a more comprehensive data collection method than simple public profile scraping.

Scraping Suspected, Not a Breach

Technical analysis by Ransomnews indicates the data is genuine and recent. However, the absence of passwords, password hashes, or payment information suggests the data was not obtained via a direct system breach. Instead, evidence points to data scraping, as the records were stamped across nine consecutive days in daily batches, a pattern consistent with a scheduled collection job rather than a single moment of compromise.

Data Authenticity Confirmed

Researchers verified the authenticity of the data by decoding timestamps embedded in account UUIDs. By comparing these generation timestamps with account registration dates across 200,000 sample records, a 100% match rate was achieved. This level of precision would be impossible to fake without access to actual Chess.com-issued identifiers down to the millisecond.

Impact on Users

While the absence of passwords and payment data mitigates the most severe risks, the exposure of personal information like email addresses and real names could still lead to phishing attempts or targeted spam. Users should remain vigilant for suspicious communications, although immediate password changes are not indicated as necessary due to this specific leak.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Sep 13

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A 15.5 GB file containing over 7.3 million Chess.com user records, including email addresses, usernames, and internal marketing tags, appeared on data-leak forums. Analysis indicates the data is genuine and recent, but evidence suggests it was obtained through scraping over several days rather than a system hack, as no passwords or payment information were included.