Chess.com leak exposes 7.3 million users, suspected scraping
A data breach involving the online chess platform Chess.com was disclosed on Monday, revealing that personal information belonging to approximately 7.3 million registered users had been exposed. The leak, which surfaced on a public forum, included usernames, email addresses, hashed passwords and, in some cases, additional profile details. Chess.com confirmed that the compromised data originated from a collection of files that were posted online without the company’s authorization.
Security researchers who examined the leaked material identified patterns consistent with automated web‑scraping rather than a traditional intrusion of the company’s servers. The scraped data appears to have been assembled over an extended period, suggesting that an external actor systematically harvested publicly available profile information and then compiled it into a downloadable archive. Chess.com’s security team has launched an investigation, notified affected users, and urged them to reset passwords, while also implementing additional rate‑limiting and bot‑detection measures to curb future scraping attempts.
The incident underscores the growing risk that large‑scale scraping poses to platforms that host extensive user‑generated content. Although no financial data or payment details were reported as part of the breach, the exposure of email addresses and password hashes could facilitate credential‑stuffing attacks on other services. Chess.com has pledged to enhance its monitoring and to work with law‑enforcement agencies to identify the source of the scrape, while security experts advise users to employ unique, strong passwords and enable two‑factor authentication wherever possible.