ConfirmedData breach

Chess.com (2026): a data breach

In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.

The record

Identity
Chess.com (2026)identified by its domain in a verified breach record
Records affected
4,653,212 records
Data exposed
Email addresses, Geographic locations, Names, Usernames
Sector
Not recorded
Occurred
2026-08-03
Disclosed
2026-09-13
First recorded here
2026-09-13

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-09-13

Chess.com (2026): a data breach | NexaPulse