Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

7.3 cardinal Chess.com profiles leaked online: the information is genuine, but grounds points to large-scale scraping, not a server breach.
Free is simply a unusual value for stolen data, and that’s precisely what makes this listing worthy a 2nd look. A 15.5 GB record containing complete 7.3 cardinal chess.com personification records showed up connected 2 data-leak forums this week, nary cost, nary ransom demand, conscionable handed out. Ransomnews’s method analysis confirms the information is existent and recent. What it isn’t, connected the evidence, is simply a hack.

“The archive is simply a azygous 744 MB 7-Zip record that expands to a 15.5 GB tab-separated table: 1 header statement and 7,337,395 records, each pinch 38 fields. The schema is chess.com-specific throughout. Alongside the evident identifiers, email, partial email, username, personification ID, UUID, first and past name, country, location and locale, it carries level state: chess title, points, accomplishment level, premium position and label, verification and activation flags, champion standing and standing type, charismatic rating, member-since and last-login timestamps.” reads the study published by Ransomnew. “Two fields astatine the extremity are the absorbing ones. Every grounds has gam_audiences and audiences_member_of populated, Google Ad Manager assemblage segments, pinch values for illustration coach-nudge research groups, proceedings eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not floor plan data. They do not look successful chess.com’s nationalist API.”
The record carries email addresses, usernames, existent names, countries, chess ratings, subscription tiers, and thing odder: soul Google Ad Manager assemblage tags, the benignant of trading segmentation information that ne'er shows up successful chess.com’s nationalist API. Roughly three-quarters of records see an email address. There are nary passwords, nary password hashes, and nary costs information anyplace successful the file, which matters a batch for really earnestly affected users request to react.
Proving this information is genuine didn’t require rubbing chess.com’s servers astatine all. Every relationship UUID successful the record is simply a version-1 identifier, the benignant that embeds the nonstop timestamp it was generated, and researchers decoded that hidden timestamp crossed 200,000 sample records to comparison it against each account’s registration date. The lucifer complaint came backmost astatine 100%, which isn’t thing anyone could clone without possessing existent chess.com-issued identifiers down to the millisecond.
Three abstracted specifications constituent toward scraping alternatively than an existent strategy breach. The information wasn’t captured successful 1 moment, it was stamped crossed 9 consecutive days successful regular batches, the shape of a scheduled postulation occupation alternatively than a azygous database dump. About 7.4% of personification records look twice, the aforesaid accounts revisited connected different days, thing that simply doesn’t hap wrong a genuine database export.
This has happened to chess.com before, and the institution was blunt astir it astatine the time. Back successful 2023, a akin leak of 828,000 records surfaced pinch a astir identical section structure, and chess.com stated plainly,
“In November 2023 a threat character published 828,000 chess.com records pinch a near-identical section set. Chess.com’s consequence past was unambiguous: as it told Hackread, “This was NOT a information breach.” continues the report. “Our infrastructure, personnel accounts, and information specified arsenic passwords are secure.” The information had been pulled by abusing the platform’s find-friends feature, feeding successful externally originated email addresses to resoluteness them against accounts. A 2nd scrape affecting astir 476,000 users followed. This 2026 record is the aforesaid method astatine astir 9 times the scale.”
That earlier incident came from abusing the platform’s find-friends characteristic to resoluteness outer email lists against existent accounts; this caller record looks for illustration the aforesaid method moving astatine astir 9 times the scale.
One item doesn’t fresh a purely public-facing scrape, though. Advertising-audience conception information isn’t thing chess.com’s unfastened API exposes, and it appears connected each azygous statement successful this file, which suggests whoever built this had entree to an authenticated aliases internal-facing endpoint alternatively than conscionable the nationalist developer tools. That’s the circumstantial mobility chess.com is champion positioned to answer, and it’s the 1 that really matters for knowing really this happened.
The relationship distributing the file, going by V0idix, isn’t monetizing thing here. The aforesaid grip has posted dozens of free database dumps crossed different unrelated companies, building estimation done measurement alternatively than done sales, which fits a collector who harvests and republishes information alternatively than personification trading entree to a caller intrusion.
None of this intends chess.com users should motion it disconnected conscionable because passwords weren’t exposed. A verified email sitting adjacent to a existent name, country, accomplishment rating, and subscription tier is much than capable earthy worldly for a convincing phishing connection astir a rank renewal aliases a fair-play dispute. The correct consequence isn’t panicking astir a hacked account, it’s treating unexpected chess.com emails pinch much suspicion than accustomed and checking whether that aforesaid email reside has turned up anyplace else, since reused credentials stay the acold much vulnerable vulnerability than thing sitting successful this peculiar file.
Follow maine connected Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Chess.com)
English (US) ·
Indonesian (ID) ·