On September 13, 2026, Have I Been Pwned indexed a Chess.com dataset containing 4,653,212 unique email addresses alongside usernames, real names and countries. No passwords were found in the data, and evidence points to large-scale scraping rather than a breach of Chess.com's systems — but the exposed combination still fuels targeted phishing. Check your email, enable 2FA, and treat any "Chess.com security alert" as suspect.
What Actually Happened
In early August 2026, a threat actor operating as V0idix advertised a 15.5 GB file said to contain 7.3 million Chess.com user records, collected between roughly July 26 and August 3, 2026. After deduplication, the dataset resolved to 4,653,212 unique email addresses. Have I Been Pwned added it to its index on September 13, 2026 under the entry "Chess.com (2026)".
The critical detail is how the data was obtained. Analysis of the dataset indicates it was scraped and aggregated from publicly accessible sources rather than extracted through a compromise of Chess.com's internal systems. Roughly 99% of the email addresses in the file had already appeared in earlier, unrelated breaches — a strong signal that this is a compiled dataset, with Chess.com account details matched against email addresses harvested elsewhere.
Scrape, Not a System Breach
This distinction matters for what you should do. A server compromise usually means credentials are at risk and a forced password reset follows. A scrape and match means your identity has been linked to an account and a set of behavioral details — which is a phishing and social-engineering problem, not primarily a password problem.
What Data Was Exposed
- Email addresses — 4,653,212 unique
- Usernames — the handle tied to your public profile
- Real names — where users supplied them
- Country / geographic location
- Account details — reportedly including player ratings, subscription tier and internal advertising tags
Notably absent: no passwords or password hashes were observed anywhere in the dataset. That is genuinely good news and the single biggest reason this incident is less severe than it first appears.
Why "Only Emails" Is Still a Problem
An email address on its own is low value. An email address tied to your real name, your country, your chess rating and whether you pay for a subscription is a phishing kit. It lets an attacker write a message that knows things about you — and specificity is exactly what makes people click.
Step 1: Check Whether You Are in the Dataset
Go to haveibeenpwned.com and search your email address. If "Chess.com (2026)" appears in your results, your address was in the file. Check every address you might have used to register — an old personal account, a Gmail alias, a work address from years ago.
If you are not listed, you may still have been affected: the dataset was deduplicated, and HIBP only indexes what it receives.
Step 2: Turn On Two-Factor Authentication
Chess.com supports two-factor authentication. Enable it in your account security settings now, even though no passwords leaked. Attackers who know your username and email will try credential stuffing with passwords from the other breaches those same addresses appeared in — and 2FA is what stops a reused password from becoming an account takeover.
Use an authenticator app rather than SMS where you have the choice. SMS codes can be intercepted through SIM-swap attacks, and your exposed name plus country makes a SIM-swap pretext easier to construct.
Step 3: Change Your Password If You Reused It
No passwords were in this dataset, so a Chess.com password change is not strictly required. But if the password on your Chess.com account is one you also use on your email, bank, or any other account, change it everywhere now. An attacker with your email address and a password from an older breach will try that pair across dozens of services automatically.
Use a password manager and give every account a unique, long, randomly generated password. That single habit neutralizes credential stuffing entirely.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Expect Targeted Phishing — and Verify Everything
This is the realistic threat from this incident. Over the coming weeks, expect emails that reference:
- Your Chess.com account being suspended or requiring "verification"
- A tournament invitation or prize notification
- A subscription renewal, billing failure, or refund
- A "security alert" about this very data leak, urging you to log in and check
That last one is the most effective, because it is true enough to be believable. The rule is simple: never log in through a link in an email. Type chess.com into your browser directly, or use your existing bookmark. If there is a genuine problem with your account, it will be waiting for you when you get there.
Check the sender domain carefully. Lookalikes such as chess-com.net, chesscom-support.com or chess.com.security-check.net are trivial to register and read as legitimate at a glance.
Step 5: Tighten What Your Public Profile Exposes
Part of what made this scrape possible is how much is publicly readable on gaming and community platforms. Review your Chess.com profile and remove your real name, location and any linked social accounts if you do not need them public. Do the same across other community sites where you use the same username — a shared handle is precisely what lets a scraper stitch separate profiles into one dossier.
Step 6: Reduce the Data That Made the Match Possible
Here is what most breach advice misses. This dataset is valuable because someone matched Chess.com account data against email addresses collected from prior breaches. That matching gets easier the more of your information is already published in public — and data broker and people-search sites are the largest single supply of it.
Those sites publish your name, current and former addresses, phone numbers, email addresses, age and relatives on free, indexable pages. When an attacker has your email from this leak, a broker profile is what turns it into a full identity: a home address to reference, a relative's name to impersonate, a phone number to target.
PrivacyOn removes your personal information from 100+ data broker sites and keeps removing it when brokers re-list you, which they routinely do. It also includes dark web monitoring, so if your email or credentials surface in the next dump you hear about it early rather than months later. Family plans cover up to 5 people from $8.33/month.
Run a free PrivacyOn scan to see how much of your personal data is currently published on broker sites — it is usually far more than people expect.
What You Do Not Need to Do
Breach panic leads to wasted effort. Based on what is actually in this dataset:
- You do not need to freeze your credit over this incident alone. No Social Security numbers, financial details, or government IDs were involved.
- You do not need to delete your Chess.com account. The data is already out; closing the account does not retract it.
- You do not need to pay anyone claiming they can delete your record from the leaked file. Nobody can. Files that are already circulating cannot be recalled.
Frequently Asked Questions
Was Chess.com actually hacked?
The available evidence indicates no. Analysis of the dataset points to scraping and aggregation from publicly accessible sources rather than a compromise of Chess.com's internal systems, and about 99% of the exposed email addresses had already appeared in earlier, unrelated breaches. That suggests the file was assembled by matching Chess.com account details against addresses harvested elsewhere, not by breaking into Chess.com's servers.
Were Chess.com passwords leaked?
No. No passwords or password hashes were observed in the dataset. You are not required to change your Chess.com password because of this incident — but if you reused that password on your email, bank, or any other account, change it everywhere immediately, because attackers will pair your leaked email with passwords from older breaches and try them automatically.
How do I know if I was affected by the Chess.com leak?
Search your email address at haveibeenpwned.com. If "Chess.com (2026)" appears in your results, your address was in the 4,653,212-record dataset indexed on September 13, 2026. Check every address you may have registered with, including old or alias addresses you no longer use day to day.
What is the real risk from this data leak?
Targeted phishing and social engineering. Your email address paired with your real name, country, chess rating and subscription status lets an attacker write a message that appears to know you — a fake tournament invite, a billing problem, or a "security alert about the Chess.com leak." Specificity is what gets people to click. Never log in through an emailed link; navigate to chess.com directly.
Should I freeze my credit after the Chess.com breach?
Not on the basis of this incident alone. The dataset contained no Social Security numbers, financial account details, or government IDs, so the direct identity-theft risk is low. A credit freeze is still a sound general precaution and is free at all three bureaus — it is simply not the urgent response here. Enabling two-factor authentication is.
How can I stop my data being used in the next leak like this?
You cannot recall data already circulating, but you can shrink what is available to combine with it. Aggregated leaks get their power from matching one exposed detail against publicly published personal information — and data broker sites are the biggest source of that. Removing yourself from those sites means the next leak that includes your email has far less to attach to it. PrivacyOn automates removal across 100+ brokers, re-removes you when they re-list, and adds dark web monitoring so you are alerted early. Start with a free scan.