A recent leak exposed 7.3 million Chess.com user profiles, attributed to large-scale data scraping rather than a server breach. The leaked file, a 15.5 GB compressed archive, included various user data fields such as usernames, emails, real names, countries, and chess ratings, but no sensitive information like passwords or payment data. Researchers verified the authenticity of the data by matching account creation timestamps.
The leak is reminiscent of a previous incident in 2023 where a smaller batch of data was leaked through similar scraping methods. Notably, the recent file also contained marketing data not available via Chess.com's public API, indicating potential access to private endpoints. Users are advised to treat emails from Chess.com with increased caution, despite the absence of exposed passwords.