In August 2026, approximately 4.6 million unique Chess.com user records including names, usernames, email addresses, and geographic locations were posted online, with analysis suggesting the data was obtained through scraping.
Loading page…
Loading page…
In August 2026, approximately 4.6 million unique Chess.com user records including names, usernames, email addresses, and geographic locations were posted online, with analysis suggesting the data was obtained through scraping.
According to Have I Been Pwned (HIBP), in August 2026 a dataset allegedly sourced from Chess.com was posted online. The dataset contained 7.3 million rows, of which 4.6 million contained unique email addresses. Analysis of the data indicated it was likely obtained through scraping rather than a direct system intrusion.
HIBP noted that when the data was ingested, approximately 99% of the email addresses had already appeared in prior breach datasets, which further supports the scraping hypothesis.
According to HIBP, the exposed data included email addresses, usernames, names, and country-level geographic locations, as well as other information related to users' Chess.com accounts.
Any Chess.com user whose profile information was publicly accessible may be affected. HIBP reports approximately 4.6 million unique email addresses were present in the dataset.
Check whether your email address appears in this breach via HIBP. While no passwords or financial data are reported to have been exposed, the combination of name, email, username, and location can be used in phishing or social engineering attacks. Be cautious of unsolicited emails referencing your Chess.com account, and consider using a unique email alias for gaming platforms going forward.