More than 7.3 million Chess.com user profiles are circulating on two leak forums in a dump posted at no charge. Analysts verified the records as genuine while pointing to a collection pattern that does not fit a server intrusion.
The archive expands to a tab-separated table with 7,337,395 rows and 38 fields per record, including email addresses, usernames, real names, countries, chess ratings, and subscription tiers. Roughly three-quarters of records carry an email address. No passwords, hashes, or payment data appear anywhere in the file.
Authenticity checks did not require touching Chess.com’s systems. Each UUID carries a version-1 format that embeds the exact moment of generation; decoding those timestamps across 200,000 records produced a perfect match against registration dates. Fabricating that consistency without real Chess.com-issued identifiers is not practical.
Several details suggest a collection job rather than a database dump. Records were stamped across nine consecutive days in daily batches, about 7.4% of accounts appear twice as users were revisited on different days, and the schema closely mirrors a 2023 leak of 828,000 records that Chess.com attributed to abuse of its find-friends feature. That earlier incident resolved external email lists against real accounts; this file looks like the same technique at roughly nine times the scale.
One detail does not fit a purely public scrape: every row carries internal Google Ad Manager audience segments that do not appear in Chess.com’s public API. That suggests an authenticated or internal-facing endpoint was involved, a question only Chess.com can answer.
Even without exposed passwords, a verified email paired with a real name, country, and rating is solid phishing material. Users should treat unexpected Chess.com messages with suspicion and check whether the same email has appeared in other dumps.

