Illustrative image generated with AI
Chess.com: 7.3 Million Profiles Exposed, Data Points to Large-Scale Scraping
Chess.com exposes 7.3 million user profiles in a data leak, likely from scraping. Includes emails, ratings, and Google Ad segments, with phishing risks.
Text generated by artificial intelligence, published without human review. AI transparency
Free archive published with 7,337,395 records
An archive containing data linked to 7,337,395 Chess.com users has been published for free on two forums dedicated to distributing stolen data. Publicly released analysis dated August 14, 2026 considers the material authentic and recent, but found insufficient evidence to classify it as a compromise of the platform’s servers.
The file is a 744 MB 7-Zip archive. Once extracted, it becomes an approximately 15.5 GB tab-delimited table containing a header row and 7,337,395 records. Each row contains 38 fields.
No specific software versions are involved. The exposure concerns profile data and certain elements belonging to Chess.com’s commercial infrastructure.
The fields include:
- email address and partially masked email address;
- username, user ID, and UUID;
- first and last name;
- country, location, and locale settings;
- chess title;
- rating, skill level, and peak rating;
- official rating type;
- premium subscription status and plan;
- verification and activation indicators;
- registration date and last login.
An email address appears in roughly three-quarters of the records. The combination of real name, geographic location, rating, and subscription details makes the dataset useful for targeted campaigns, even though it does not directly contain login credentials.
UUIDs confirm the data’s origin
The technical verification did not require access to Chess.com’s systems. The UUIDs in the records are version 1 identifiers, a type that embeds the precise generation time in the value itself.
Researchers decoded the timestamp hidden in 200,000 sample records and compared it with the registration time of the corresponding accounts. The match was complete: the UUID timestamps aligned with the registration dates, with accuracy down to the millisecond.
Such a result is difficult to reconcile with fabricated or randomly generated data. Instead, it indicates that at least the identifiers genuinely originated from the platform or from a system that received them directly from Chess.com.
This alone does not prove an intrusion into internal databases. It does, however, confirm that the material consists of real data attributable to the listed accounts.
Why scraping is the leading hypothesis
The dataset’s structure suggests repeated automated collection rather than a single complete database export.
The records were generated in daily batches spread across nine consecutive days. This pattern is consistent with a scraper progressively querying the platform, rather than an attacker downloading a single copy of the database.
The duplicates support this interpretation as well. Approximately 7.4% of the accounts appear twice, with the same account recorded on different days. This repetition is consistent with successive visits by an automated tool and incremental data collection.
There is also a technical precedent. The find-friends feature had previously been abused to check external lists of email addresses and determine which ones matched real accounts. In 2023, a similar archive containing approximately 828,000 records emerged, followed by another collection involving roughly 476,000 users.
The new dataset appears compatible with the same technique, but on a scale estimated to be about nine times larger than the previous incident. At the time, Chess.com said it was not a data breach and that its infrastructure, accounts, and passwords remained secure.
Advertising fields are the most significant anomaly
The detail that prevents the entire incident from being confidently attributed to ordinary public scraping is found in the table’s final two fields: gam_audiences and audiences_member_of.
Both fields are populated in every record and contain audience segments associated with Google Ad Manager. Examples include experimental groups for promoting coaches, users eligible for trial periods, inactive accounts, and segments based on rating ranges.
This information belongs to the marketing stack and is not normally visible on user profiles. According to the technical analysis, it is also not exposed through Chess.com’s standard public developer API.
How the data was obtained therefore remains unclear. Possibilities include access to an authenticated endpoint, abuse of an interface intended for internal components, or use of a session with privileges exceeding those available to a regular visitor.
This detail is not sufficient to prove a server compromise. It does show, however, that at least part of the collection may have exploited a non-public or undocumented attack surface. For Chess.com, this is the area requiring the most urgent investigation.
No passwords, but phishing risk is real
The material does not appear to contain passwords, password hashes, or payment data. The archive therefore does not directly enable access to Chess.com accounts using credentials contained in the file.
The risk is nevertheless significant. An attacker may have access to email addresses, names, countries, locations, ratings, subscription status, and indicators of user activity. These details can make messages far more convincing than generic phishing campaigns.
A fraudulent email could impersonate:
- a subscription renewal request;
- an offer for a premium trial period;
- a fair-play violation notice;
- an alert about a rating or recent activity;
- an account verification request.
A confirmed email address can also support attacks against other services. Anyone who reuses the same password across multiple platforms remains exposed to credential-stuffing attempts, while detailed profile information can facilitate social engineering and fraudulent account-recovery operations.
What users should do
Chess.com users should treat messages referencing their rating, subscription, games, or actual account activity with suspicion.
To verify a renewal, dispute, or login request, users should open the official website or app directly rather than clicking links in emails. Passwords should not be reused across different services; if the same password has been used elsewhere, it should be changed on those platforms as well.
Users should enable multifactor authentication where available and check whether their email address has appeared in other known data exposures. Particular caution is warranted when messages include the user’s real name or apparently private details such as their rating and subscription tier.
For Chess.com, priority checks include the fields linked to Google Ad Manager, authenticated and internal endpoints, abuse of find-friends, protections against email-based account enumeration, and anti-automation systems. It is currently unknown whether the platform has publicly confirmed the archive’s origin or implemented specific countermeasures.
Sources
This article is an original reworking based on the sources below.
