15,214 Passwords From the International Chess Federation Just Leaked
The International Chess Federation Data Breach: What HEROIC Analysts Found
HEROIC analysts identified a dataset tied to the International Chess Federation's official online portal, based in Switzerland. The dataset is dated August 26, 2018, and was shared on a hacking forum. It affects 15,214 accounts and exposes email addresses paired with plaintext passwords.
Why 15,214 Plaintext Passwords From a Global Sports Federation Matter
The passwords in this leak were stored in plaintext, meaning the International Chess Federation never hashed or encrypted them before this data was exposed. That is 15,214 working logins sitting in a hacking forum, readable by anyone who downloads the file, with no cracking or guessing required. Because this is an international organization with members across many countries, the potential reach of a single leak like this extends well beyond one country's user base.
What Was Exposed
- Email addresses
- Plaintext passwords (stored without hashing or encryption)
Why This Matters for International Chess Federation Members
Attackers who obtain plaintext email and password pairs typically test them against other websites through credential stuffing, hoping people reused the same login elsewhere. If any of the 15,214 affected members reused their federation password on an email account or another platform, they are exposed to account takeover. The paired email address also enables targeted phishing, since a message referencing a real, valid account is far more convincing than a random spam attempt.
How This Database and Combolist Leak Likely Happened
This breach is classified as both a database exposure and a combolist. A database exposure typically means an attacker found a vulnerability in the portal's backend and extracted the user authentication table directly, plaintext passwords included. That data then commonly gets reformatted into a combolist, a simple file pairing each email address with its password, making it easy for other criminals to feed the credentials into automated tools and test them against other websites at scale.
Check If You're Affected by the International Chess Federation Breach
If you have ever registered on the International Chess Federation's official portal, it is worth checking whether your email address appears in this leak. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including this one, so you can find out in seconds and update any reused passwords.
Breach Breakdown
15,214 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds