LmCast :: Stay tuned in

Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping

Recorded: Sept. 14, 2026, 5:01 a.m.

Original Summarized

Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping

Home
Cyber Crime
Cyber warfare
APT
Data Breach
Deep Web
Hacking
Hacktivism
Intelligence
Artificial Intelligence
Internet of Things
Laws and regulations
Malware
Mobile
Reports
Security
Social Networks
Terrorism
ICS-SCADA
Crypto
POLICIES
Contact me

MUST READ

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
 | 
Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION
 | 
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read - Exploited Within 24 Hours
 | 
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
 | 
Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons
 | 
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
 | 
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
 | 
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
 | 
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
 | 
More Capable AI, Not Enough Guardrails
 | 
A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm
 | 
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
 | 
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
 | 
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
 | 
Google fixes the seventh actively exploited Chrome zero-day of 2026
 | 
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
 | 
Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
 | 
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
 | 
Hackers Drain $320 Million From Liquid Network, Then Return Most of It
 | 
WeChat Worm Can Hijack Accounts Without Victims Answering Calls
 | 

Home
Cyber Crime
Cyber warfare
APT
Data Breach
Deep Web
Hacking
Hacktivism
Intelligence
Artificial Intelligence
Internet of Things
Laws and regulations
Malware
Mobile
Reports
Security
Social Networks
Terrorism
ICS-SCADA
Crypto
POLICIES
Contact me

Home
Breaking News
Cyber Crime
Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

Pierluigi Paganini
August 14, 2026

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach.
Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, is a hack.

“The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and 7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious identifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it carries platform state: chess title, points, skill level, premium status and label, verification and activation flags, best rating and rating type, official rating, member-since and last-login timestamps.” reads the report published by Ransomnew. “Two fields at the end are the interesting ones. Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not profile data. They do not appear in chess.com’s public API.”
The file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something odder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in chess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no password hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users need to react.
Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a version-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that hidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match rate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued identifiers down to the millisecond.
Three separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on different days, something that simply doesn’t happen inside a genuine database export.
This has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar leak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly,
“In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set. Chess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the report. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled by abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them against accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique at roughly nine times the scale.”
That earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against real accounts; this new file looks like the same technique running at roughly nine times the scale.
One detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something chess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this had access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the specific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding how this happened.
The account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted dozens of free database dumps across other unrelated companies, building reputation through volume rather than through sales, which fits a collector who harvests and republishes data rather than someone selling access to a fresh intrusion.
None of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email sitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a convincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t panicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and checking whether that same email address has turned up anywhere else, since reused credentials remain the far more dangerous exposure than anything sitting in this particular file.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Chess.com)

facebook
linkedin
twitter

Chess.com
Cybercrime
data leak
Hacking
hacking news
information security news
IT Information Security
Pierluigi Paganini
Security Affairs
Security News

you might also like

Pierluigi Paganini
September 13, 2026

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
Read more

Pierluigi Paganini
September 13, 2026

Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION
Read more

leave a comment

newsletter

Subscribe to my email list and stay up-to-date!

recent articles

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
Breaking News / September 13, 2026

Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION
Security / September 13, 2026

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read - Exploited Within 24 Hours
Hacking / September 13, 2026

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
Cyber Crime / September 13, 2026

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons
Artificial Intelligence / September 12, 2026

To contact me write an email to:
Pierluigi Paganini :
[email protected]

LEARN MORE

QUICK LINKS
Home
Cyber Crime
Cyber warfare
APT
Data Breach
Deep Web
Hacking
Hacktivism
Intelligence
Artificial Intelligence
Internet of Things
Laws and regulations
Malware
Mobile
Reports
Security
Social Networks
Terrorism
ICS-SCADA
Crypto
POLICIES
Contact me

Copyright@securityaffairs 2024

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.Cookie SettingsAccept AllManage consent

Close

Privacy Overview
This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.

Necessary

Necessary

Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT

A leak involving Chess.com exposed approximately 7.3 million user profiles, a situation analyzed by Pierluigi Paganini who asserts that while the data is authentic, the evidence strongly points toward large-scale automated scraping rather than a direct server intrusion. The leaked material consisted of a 15.5 gigabyte file containing over seven million records, structured in a tab-separated format with thirty-eight fields. These records included standard identifiers such as usernames, email addresses, full and partial names, country, location, and specific chess metrics like ratings, subscription tiers, and member since dates. Crucially, the data also included internal marketing segmentation fields, specifically Google Ad Manager audience tags, which are not accessible through Chess.com’s public application programming interface, indicating the source had access to authenticated or internal-facing endpoints.

The analysis of the data’s authenticity was performed without accessing Chess.com's servers, using version one identifiers embedded in the account UUIDs. By comparing these identifiers against registration dates across a large sample, researchers confirmed a one hundred percent match rate, demonstrating that the identifiers possessed the necessary precision to exclude fakery. A key aspect supporting the scraping hypothesis was the timing of the data collection; the data was not dumped instantaneously but was gathered in daily batches over nine consecutive days, characteristic of a scheduled collection job rather than a single database extraction. Furthermore, the observation that roughly three-quarters of the records contained email addresses, combined with the absence of sensitive information like passwords, password hashes, or payment details, suggests the data was primarily harvested for profile information and marketing segmentation.

Previous incidents have provided context for this finding. In November 2023, a similar event exposed 828,000 records, which Chess.com attributed to a threat actor abusing the platform’s find-friends feature to resolve external email lists against accounts. Paganini notes that the current 2026 file appears to employ the exact same methodology, scaled up by approximately nine times, confirming that the large-scale leak leverages known platform features for data aggregation rather than a novel breach of core security infrastructure. The presence of advertising audience data is highlighted as further evidence against a simple breach, as this sensitive marketing segmentation information is not exposed via public APIs.

Given the composition of the leaked data, the potential risk to users centers on identity-based attacks. Although passwords and financial data were not exposed, the combination of real names, verified email addresses, geographical locations, and subscription statuses provides sufficient raw material for sophisticated social engineering attacks, such as phishing attempts regarding membership renewals or disputes. Consequently, the recommended response for users is to exercise heightened suspicion toward unexpected communications and to prioritize securing any reused credentials, as credential compromise remains a significantly greater threat than the specific data contained in this particular file.