A massive data leak has exposed 7.3 million Chess.com user profiles, with evidence suggesting the data was obtained through large-scale scraping rather than a server breach. The leaked data, contained in a 15.5 GB file, has been verified as genuine and recent by technical analysis1. The fact that the data is being offered for free, with no ransom demand, raises questions about the motivations behind the leak. The data was posted on two data-leak forums, and its availability has significant implications for the affected users. The lack of a breach suggests that Chess.com's servers were not compromised, but rather that the data was collected through other means, such as web scraping. This highlights the importance of protecting user data from unauthorized collection and use. The leak matters to practitioners because it underscores the need for robust data protection measures to prevent similar incidents in the future.
Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
⚡ High Priority
Why This Matters
7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach.
References
- SecurityAffairs. (2026, August 14). Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping. SecurityAffairs. https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html
Original Source
SecurityAffairs
Read original →