Suzanne Kantra/Techlicious generated by ChatGPT
A hacker posted a database on a cybercrime forum this week claiming to hold information scraped from more than 7 million Chess.com accounts. Chess.com hadn't confirmed the incident as of publication, but the security outlet Hackread, which obtained and reviewed the file, verified that a sample of the listed accounts do exist on the site.
Hackread's analysis found the file contained 7,337,396 rows, each corresponding to one account, and 4,656,791 email addresses among them, along with usernames, account IDs, names, countries, ratings, account creation dates, and last-login timestamps. Some records included avatar links and labels showing which Chess.com promotional groups an account belonged to, and a portion of the login timestamps were from just days before the leak surfaced, suggesting at least some of the data is recent.
No passwords or password hashes turned up anywhere in the file, according to Hackread, so this leak alone can't be used to log into your account.
What leaked can still arm scammers with information – your username, rating, and country – for phishing: emails or messages designed to look like they're from Chess.com in order to steal more of your information. A message about a tournament invite, a subscription renewal, or an account security alert now carries real personal details, making it harder to spot as fake.
How the data was collected still isn't clear. The hacker described it as scraped from public profile information, but Hackread notes that email addresses and some of the account labels found in the file aren't normally visible on public Chess.com profiles, so scraping alone doesn't fully explain how they ended up in the database. Hackread says it couldn't independently confirm whether the data came from an exposed interface, unauthorized account access, or another source.
Chess.com has been through this before. A hacker posted 800,000 scraped records in November 2023, then a second batch of 476,000 records days later.
Normally, we recommend turning on two-factor authentication (2FA) when these incidents occur. Unfortunately, Chess.com doesn't currently offer 2FA, and has stated in the past that, "We are never going to add this for members...there is nothing so personal and sensitive that needs that level of protection."
What you can do if you have a Chess.com account is to treat any unexpected email or message referencing your account, tournaments, or billing with extra suspicion. Don't click login links inside them; go to chess.com directly instead.
Read next: The best password managers to protect your accounts