A massive data leak has exposed 7.3 million Chess.com user profiles, with evidence suggesting the data was obtained through large-scale scraping rather than a server breach. The leaked data, contained in a 15.5 GB file, has been verified as genuine and recent by technical analysis1. The fact that the data is being offered for free, with no ransom demand, raises questions about the motivations behind the leak. The data was posted on two data-leak forums, and its availability has significant implications for the affected users. The lack of a breach suggests that Chess.com's servers were not compromised, but rather that the data was collected through other means, such as web scraping. This highlights the importance of protecting user data from unauthorized collection and use. The leak matters to practitioners because it underscores the need for robust data protection measures to prevent similar incidents in the future.