[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ppxl56cqjjkh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda48825142","chess","Chess Data Breach","chess.com","2023-11-08T00:00:00.000Z","2023-11-10T02:02:26.000Z","2026-07-03T14:51:06.409Z","2026-07-18T23:47:17.491Z","Third party breach","",[],1274077,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","Geographic locations","Names","Usernames","\u003Cp>The Chess data breach is related to user records obtained from the Chess.com platform through automated data collection during the November 2023 period. Initially, more than 800,000 records were visible, and later, with the inclusion of additional records, the scope increased to 1,274,077 unique email addresses. The records include email addresses, geographic location information, names, and usernames. Password or payment card data are not listed under these records.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>When the username, name, and email address are found together, a Chess.com profile can be matched with a real person. The geographic location information, on the other hand, can show the player's country or city context. These fields do not directly provide account takeover; however, they can make fake tournament, membership, premium account, friend invite, or security alert messages more convincing.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, or address come together, attackers may approach the user as if there is a legitimate service relationship. This information alone is not proof of account takeover; however, it provides a strong starting point for fake support messages, delivery notifications, password reset attempts, and personalized fraud flows. Since the record does not contain a password field, it should not be said to the user that their password has been leaked. Nevertheless, if the same email address appears with a password in other breaches, attackers can prepare more personalized messages using the Chess profile. The context of the gaming community increases the risk of social engineering.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is recorded as November 8, 2023. The current scope is 1,274,077 affected email addresses; the previous figure of 827,620 has been updated with additional records. Security records indicate that the data was obtained through an automated collection method via Chess.com and includes email, name, username, and location fields.\u003C\u002Fp>\u003Cp>It should be made clear while explaining the scope that this incident is not a password or payment information leak. In addition, automatically collected profile data may not always have the same field quality. The correct warning to the user is that their account can match with the gaming community identity and that the risk of targeted messages increases.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have a Chess.com account, use their username and name information on their profile, share location information, or open accounts on other gaming platforms with the same email address. Competitive players, club members, and tournament participants can be targeted with fake invitation messages.\u003C\u002Fp>\u003Cp>There is a risk of cross-platform matching for people who use the same username on different games, social media, or forums. Location information can make messages related to local tournaments, clubs, or events appear more realistic. Users should be cautious of messages containing account security warnings or reward promises.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching area should check that they are using a unique password on their Chess.com account, and they should also review security settings on other gaming platforms where they use the same email and username. Even if a password is not present in the record, leaving a password repetition is a proper precaution.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or application of the relevant service. The fact that the caller knows the name, email, address, or past transaction information does not prove they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a password manager, unique passwords, two-factor authentication on applicable accounts, and the habit of removing unnecessary personal information from accounts reduce risk. Reusing the same email address across different platforms makes it easier to combine different breaches; therefore, using separate email or alias addresses for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Since a username can become a permanent identity in gaming communities, using the same username across different platforms should be carefully considered. If there is unnecessary real name or location information in the profile, it should be reduced, and club and tournament messages should be verified from the official platform.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in this record or not. A positive result does not necessarily mean that all data fields definitively belong to that user; however, it should be considered a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this data set and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the Chess.com profile information matches the email address and increases the risk of game-themed phishing. A negative result means that there is no match in this record; the possibility of the same player email appearing on other gaming platforms should also be checked.\u003C\u002Fp>","Chess Data Breach (1.3 Million Reported Records)","Chess Data Breach. 1.3 Million reported records were reported. Reported data: Email addresses, Geographic locations, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fchess_com.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Chess","Gaming \u002F Correspondence Chess","United States"]