Free 15.5 GB dump puts 7.3 million Chess.com accounts at risk

A free archive with 7.3 million Chess.com records looks like large-scale scraping, though one internal-facing detail needs explaining.

CSBadmin
2 Min Read

More than 7.3 million Chess.com user profiles are circulating on two leak forums in a dump posted at no charge. Analysts verified the records as genuine while pointing to a collection pattern that does not fit a server intrusion.

The archive expands to a tab-separated table with 7,337,395 rows and 38 fields per record, including email addresses, usernames, real names, countries, chess ratings, and subscription tiers. Roughly three-quarters of records carry an email address. No passwords, hashes, or payment data appear anywhere in the file.

Authenticity checks did not require touching Chess.com’s systems. Each UUID carries a version-1 format that embeds the exact moment of generation; decoding those timestamps across 200,000 records produced a perfect match against registration dates. Fabricating that consistency without real Chess.com-issued identifiers is not practical.

Several details suggest a collection job rather than a database dump. Records were stamped across nine consecutive days in daily batches, about 7.4% of accounts appear twice as users were revisited on different days, and the schema closely mirrors a 2023 leak of 828,000 records that Chess.com attributed to abuse of its find-friends feature. That earlier incident resolved external email lists against real accounts; this file looks like the same technique at roughly nine times the scale.

One detail does not fit a purely public scrape: every row carries internal Google Ad Manager audience segments that do not appear in Chess.com’s public API. That suggests an authenticated or internal-facing endpoint was involved, a question only Chess.com can answer.

Even without exposed passwords, a verified email paired with a real name, country, and rating is solid phishing material. Users should treat unexpected Chess.com messages with suspicion and check whether the same email has appeared in other dumps.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.