A 15.5 GB dataset allegedly sourced from Chess.com was posted for free on an underground forum, containing 7.3 million records and approximately 4.6–4.7 million unique email addresses. The records include usernames, names, countries, and Chess.com account-related information.
Have I Been Pwned added the data to its breach corpus but assessed that it was likely collected by scraping publicly accessible Chess.com web or API data rather than by compromising protected Chess.com systems. About 99% of the email addresses had appeared in earlier breach datasets; nevertheless, the combined account details can enable convincing chess-themed phishing, impersonation, and fraud.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
A 15.5 GB dataset reportedly containing about 7.3 million rows of Chess.com-associated records was published for free download on an underground forum. The records included email addresses, usernames, names, countries, and Chess.com account-related information, and were not presented as an extortion attempt.
A dataset associated with Chess.com users was reportedly collected between July 26 and August 3, 2026. Subsequent analysis assessed that the information was likely gathered through large-scale scraping of publicly accessible website or API data rather than a compromise of protected Chess.com systems.
Have I Been Pwned added the Chess.com-associated dataset to its breach corpus and found that 99% of its email addresses had appeared in previous breach datasets. This high reuse rate was cited as further support for the conclusion that the collection resulted from scraping rather than a direct Chess.com breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.