A large dataset containing information on more than 7.3 million Chess.com users has surfaced on data-leak forums without any ransom demand or price. The 15.5 GB file includes detailed user data such as email addresses, usernames, real names, countries, chess ratings, subscription levels, and internal marketing segmentation tags. Notably, the leak does not contain passwords, password hashes, or payment information.
Technical analysis indicates the data is genuine and recent, but evidence points to scraping rather than a traditional hack. The records were collected over nine consecutive days in batches, consistent with scheduled data harvesting. Duplicate entries for some users further support this conclusion. The dataset includes internal Google Ad Manager audience tags, which are not available through Chess.com’s public API, suggesting the scraper may have had access to internal or authenticated endpoints.
This incident resembles a previous 2023 leak involving 828,000 records, which Chess.com confirmed was not a breach but the result of abusing the platform’s "find-friends" feature. That method involved resolving external email lists against Chess.com accounts. The current leak appears to be a similar technique executed on a much larger scale.
The individual distributing the data, known as V0idix, has shared multiple free data dumps from various companies, indicating a pattern of collecting and publishing data rather than selling it.
While no passwords were exposed, the combination of verified emails, real names, and subscription details could enable targeted phishing attacks. Users are advised to treat unexpected Chess.com communications with caution and monitor whether their email addresses have appeared in other data leaks. Chess.com has not publicly commented on this latest incident, and the presence of internal marketing data raises questions about potential access to non-public systems.
This event highlights ongoing challenges in protecting user data on popular platforms and the risks posed by scraping techniques that exploit legitimate features or internal endpoints.