ConfirmedData breach
Chess.com (2026): a data breach
In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.
The record
- Organisation
- Chess.com (2026) →
- Identity
- Chess.com (2026)identified by its domain in a verified breach record
- Records affected
- 4,653,212 records
- Data exposed
- Email addresses, Geographic locations, Names, Usernames
- Sector
- Not recorded
- Occurred
- 2026-08-03
- Disclosed
- 2026-09-13
- First recorded here
- 2026-09-13
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-09-13