828326 Chess Player Profiles Stolen and Leaked Online
HEROIC analysts traced a database dump containing Chess user records to a well-known hacking forum, with the data dated to November 8, 2023. The breach covered 828,326 unique user accounts and included email addresses, usernames, and full names, as well as geographic location data tied to each account. Chess is one of the most visited gaming platforms in the world, which means the affected user pool is broad and internationally distributed. While no passwords were included in this particular dataset, the combination of real names, emails, and usernames still creates meaningful risk for affected players.
Why Losing Your Username and Email to Attackers Is a Real Problem
It may seem like usernames and email addresses are low-stakes data, but that thinking is exactly what attackers count on. Your Chess username is often tied to your real name, your public profile, and your account history. Combined with your email, it gives criminals everything they need to impersonate you or attempt to access your account through password reset flows. Attackers also use this kind of data to run phishing campaigns that look genuine, addressing you by name and referancing your Chess activity. Geolocation data adds another layer, allowing criminals to craft messages that reference local details to make them seem more credible.
What Was Exposed in the Chess Breach
- Email Address
- Username
- First Name
- Last Name
- Geographic Location
Why Chess Player Data Feeds Credential Stuffing and Account Takeover
Even without a password in the dataset, this breach creates real downstream risk. Criminals take leaked email addresses and run them through credential stuffing tools that test thousands of known password combinations automatically. If you have ever reused a password across services, this is how your other accounts get broken into. Chess players tend to have accounts on multiple gaming platforms, forums, and streaming services, all of which become targets the moment your email address is confirmed as active and in circulation. Account takeovers on gaming platforms can also have financial consequences, since many accounts hold payment methods or virtual currency.
How Database Breaches Affect Gaming Platforms
Gaming platforms are frequent targets for database breaches because they maintain large user bases with detailed profile data, and they often grow rapidly without matching security investment. A database breach occured when an attacker exploits a vulnerability in the website, API, or server infrastructure to gain access to the stored user records. In the Chess case, more than 800,000 records were exfiltrated and shared publicly on a hacking forum, making the data recieved by an unknown number of threat actors. Once data is posted to a public forum, it spreads quickly and becomes almost impossible to contain. The breach may also be used as a starting point for building larger combined datasets.
Check If Your Chess Account Data Was Exposed
If you have a Chess account, your email address, real name, and username may already be in the hands of attackers. HEROIC's free breach scanner searches more than 400 billion records to show you every breach your information appears in. Knowing where your data has been exposed is the first step toward protecting your other accounts. Run a free scan at HEROIC now and find out exactly where you stand.
Breach Breakdown
828,326 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds