A 15.5 GB file with 7,337,395 Chess.com user records appeared free on two data-leak forums. Data includes emails, usernames, real names, countries, ratings, subscription tiers, and internal Google Ad Manager audience tags. No passwords or payment data.
Ransomnews verified 169,287 of 169,289 valid UUIDs carry embedded creation timestamps matching member_since values — genuine Chess.com-issued UUIDs. Capture dates run July 26 to August 3, 2026 in daily batches with 7.4% repeat users, indicating incremental scraping rather than a database export.
Internal advertising-audience fields are not exposed via Chess.com’s public API. Precedent: November 2023 scrape of 828,000 records via find-friends feature abuse; Chess.com stated it was NOT a data breach. This 2026 file is the same technique at roughly nine times the scale. HIBP indexed 4,653,212 unique emails September 13, 2026; 99% matched prior breaches.