A 15.5 GB file containing 7,337,395 Chess.com user records has been distributed on data-leak forums. The file, offered at no cost, includes a wide range of user information such as email addresses, usernames, user IDs, real names, countries, chess titles, skill levels, premium status, and various rating data. Approximately three-quarters of the records contain an email address.
Notably, the leaked data also contains internal Google Ad Manager audience segments, such as 'coach-nudge experiment groups' and 'lapsed-user cohorts'. These marketing-stack fields are not typically available through Chess.com's public API, suggesting a more comprehensive data collection method than simple public profile scraping.
Technical analysis by Ransomnews indicates the data is genuine and recent. However, the absence of passwords, password hashes, or payment information suggests the data was not obtained via a direct system breach. Instead, evidence points to data scraping, as the records were stamped across nine consecutive days in daily batches, a pattern consistent with a scheduled collection job rather than a single moment of compromise.
Researchers verified the authenticity of the data by decoding timestamps embedded in account UUIDs. By comparing these generation timestamps with account registration dates across 200,000 sample records, a 100% match rate was achieved. This level of precision would be impossible to fake without access to actual Chess.com-issued identifiers down to the millisecond.
While the absence of passwords and payment data mitigates the most severe risks, the exposure of personal information like email addresses and real names could still lead to phishing attempts or targeted spam. Users should remain vigilant for suspicious communications, although immediate password changes are not indicated as necessary due to this specific leak.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A 15.5 GB file containing over 7.3 million Chess.com user records, including email addresses, usernames, and internal marketing tags, appeared on data-leak forums. Analysis indicates the data is genuine and recent, but evidence suggests it was obtained through scraping over several days rather than a system hack, as no passwords or payment information were included.