Hacker Leaks 7 Million Scraped Chess.com User Records

Hacker Leaks 7 Million Scraped Chess.com User Records

A hacker leaked a 14.5GB database with 7.3 million scraped Chess.com records, including 4.6 million email addresses, user profile details and recent login data.

Listen to this article

0:00

Press play to start listening

A hacker has released a 14.5GB database said to contain information linked to more than seven million Chess.com accounts, including millions of email addresses and account activity details. The person responsible claims the information was scraped from the online chess platform.

The material first appeared on a cybercrime forum on Wednesday, 12th of August, before being shared through Telegram. Hackread.com obtained and analysed the TSV file, which contains 7,337,396 lines and 4,656,791 email addresses.

During its review, Hackread.com found usernames, user IDs, UUIDs, full or partially hidden email addresses, names, countries, locations, membership status, ratings, account creation dates, and last-login timestamps. Some records also contained avatar links, language settings, and labels showing which Chess.com user groups or promotional categories an account belonged to.

Among the timestamps reviewed were last-login dates from August 2026, including activity recorded only days before the information was released. This suggests that at least part of the database was collected recently, although the exact collection method remains unknown.

Hacker Leaks 7 Million Scraped Chess.com User Records
Redacted screenshot from the leaked data reviewed by Hackread.com)

No Passwords

The good news is that no passwords or password hashes were observed in the entire database. The absence of passwords limits its direct use for account access, but the combination of email addresses, usernames, and personal account details still gives scammers material for convincing phishing messages and impersonation attempts.

Although the hacker described the incident as scraping, that claim does not establish how the non-public information was obtained. Public Chess.com profiles can display usernames, ratings, and activity, but email addresses and some of the account labels found in the file are not normally visible on profile pages. Hackread.com could not independently confirm whether the data came from an exposed interface, unauthorized account access, or another source.

For context, scraping is the automated collection of information from websites, applications, or publicly accessible interfaces. A scraper can gather millions of records much faster than a person and combine them into a searchable database. A scraped database does not automatically mean the company’s internal systems were hacked, although the method used to obtain the Chess.com records has not been independently confirmed.

To test the data, Hackread.com checked a limited selection of its account details against Chess.com. The associated accounts existed, supporting the assessment that the material contains genuine information. That test does not prove every entry is current or accurate.

Hacker Leaks 7 Million Scraped Chess.com User Records
Testing the existing accounts (Image credit: Hackread.com)

Chess.com has not confirmed the incident. Hackread.com contacted the company on August 12, 2026, and received an automated acknowledgement saying its team would respond shortly. No substantive response had arrived by the time of publication.

Nevertheless, even without passwords, the information could help criminals target Chess.com members with emails referring to real usernames, ratings, locations, or membership details. Users should be cautious with unexpected messages claiming to concern account verification, tournaments, subscriptions, or security alerts.

Hacker Leaks 7 Million Scraped Chess.com User Records
Post from the hacker detailing the chess.com leak (Image credit: Hackread.com)

3rd Cybersecurity Incident in 3 Years

Chess.com has faced similar incidents before. In November 2023, a hacker released 800,000 scraped user records. Days later, a second collection containing 476,000 records was posted online.

Anyone with a Chess.com account should use a unique password, activate two-factor authentication, and avoid following login links received through unsolicited emails or messages. Users who reused their Chess.com password elsewhere should change it on every affected service.

This article will be updated based on the company’s response. Stay tuned!

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts