Over 7.3 million Chess.com user profiles have been leaked online through data leak forums, distributed without charge by an account that specializes in posting scraped databases. The 15.5 GB dataset contains email addresses, usernames, real names, geographic data, chess ratings, subscription tiers, and internal marketing segmentation fields from Google Ad Manager. Chess.com has not yet confirmed whether this represents a breach of internal systems or an abuse of platform features, though multiple technical indicators point toward the latter.
Technical analysis by security researchers verified the data's authenticity by examining UUID timestamps embedded in account identifiers. Testing 200,000 sample records showed a 100% match between the hidden timestamp in each UUID and the account's actual registration date, a correlation impossible to fabricate without access to genuine Chess.com-issued identifiers accurate to the millisecond. Approximately 75% of records include email addresses, while the dataset contains no passwords, password hashes, or payment information.
Three specific characteristics indicate systematic scraping rather than a database breach. The data was collected across nine consecutive days in daily batches rather than extracted in a single operation. About 7.4% of user records appear twice with different collection timestamps, a pattern inconsistent with standard database exports. The dataset's structure closely matches a November 2023 incident affecting 828,000 Chess.com users, where the company stated plainly that no breach had occurred and that attackers had abused the platform's find-friends feature by feeding external email lists to resolve them against existing accounts.
One element complicates the scraping theory: every record contains Google Ad Manager audience segment data, including coach-nudge experiment groups, trial eligibility flags, lapsed-user cohorts, and rating-band targeting information. These marketing fields do not appear in Chess.com's public API, suggesting the collector accessed an authenticated or internal endpoint rather than relying solely on publicly available developer tools. This discrepancy represents the key question Chess.com must address to clarify how the data was obtained.
While the absence of passwords reduces immediate account security risks, the combination of verified email addresses with real names, locations, skill ratings, and subscription status provides sufficient information for targeted phishing campaigns. Users should treat unexpected Chess.com emails with heightened suspicion, particularly messages concerning membership renewals or fair-play disputes. The greater long-term risk involves credential reuse: users who employ the same email and password combination across multiple services face exposure if those credentials have been compromised elsewhere.
Source: https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html


