Chess.com Leak Exposes 7.3 Million Users, but Evidence Points to Scraping, Not a Breach
Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping

A 15.5 GB file with over 7.3 million Chess.com records appeared free on two leak forums. Analysis confirms the data is genuine and recent, yet three clues—daily batches over nine days, 7.4% duplicate records, and embedded v1 UUID timestamps—point to large-scale scraping, not a server breach. The file includes emails, names, ratings, and subscription tiers, but no passwords or payment data. Oddly, every row carries internal Google Ad Manager audience tags, suggesting access to an authenticated endpoint.
The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump.
- Shank
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
- sidrag22
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
- dwroberts
Worth noting this was reported back in August, it’s not new