A collection of user records from the online chess platform Chess.com has surfaced on two known leak forums. As Stadt-Bremerhaven reports, the published dataset contains a total of 7,337,395 records. Chess.com is one of the world’s largest platforms where players compete in online matches, complete training sessions, and track their ratings.
What is known about the release
According to current findings, the dataset containing more than 7.3 million entries was made available on at least two leak forums. Exactly which details are included in the individual entries—such as profile names, email addresses, or identifiers—has not yet been conclusively determined based on available information.
It also remains unclear how the data was gathered. Besides direct unauthorized access to internal systems, automated scraping of publicly accessible profile APIs—where visible profile information is scraped and compiled into a single database—is also a plausible scenario.
Potential risks for registered players
Even if such collections do not contain passwords, publicly circulating datasets still pose significant risks to users. Cybercriminals frequently exploit confirmed memberships and details for targeted phishing attacks. In these schemes, attackers send forged notifications impersonating the platform to trick victims into entering their actual login credentials on counterfeit websites.
Furthermore, when passwords are reused across multiple sites, there is an increased risk of credential stuffing attacks: criminals use automated tools to test previously breached login combinations on other services such as Chess.com to take over accounts.
Best practices: Security measures for account holders
As a precaution, users with a Chess.com account should take the following steps to secure their profile:
- Reset your password: Change your account password and use a unique, strong password that is not used for any other online service.
- Enable two-factor authentication: Check your account settings to see if two-factor authentication (2FA) can be enabled to secure logins via a second channel.
- Stay vigilant regarding messages: Do not hastily click on links in unexpected emails or messages that claim to originate from Chess.com and ask you to confirm your credentials.
Sources: Stadt-Bremerhaven















