Researchers Flag Net-Chess Breach: 39,745 Accounts Leaked in 2017
HEROIC analysts uncovered the Net-Chess breach while scanning data shared across hacking forums in late 2017. The incident occured on September 26, 2017 and exposed records belonging to approximately 39,745 users of this US-based online chess platform. The compromised database contained email addresses alongside a troubling mix of password formats including plaintext, MD5 hashes, and PHPass hashes, suggesting the platform had no consistent security standard for protecting user credentials.
The Danger of Mixed Password Security: Plaintext and Weak Hashes Combined
The Net-Chess breach stands out because it reveals three different levels of password storage in a single database, and none of them are truly safe. Plaintext passwords are accessable to any attacker immediately. MD5 hashes are considered broken and can be cracked within seconds using freely available tools. Even the stronger PHPass hashes can be reversed with enough computing power. Together, this mix means virtually every exposed password can be recovered and used in attacks against other services where users recycled the same credentials.
What Was Exposed in the Net-Chess Breach
- Email Address
- Password Hash
- Plaintext Password
Why a Niche Gaming Breach Can Unlock Your Other Accounts
Most people do not use a unique password for every website they visit. When a small platform like Net-Chess is breached, attackers do not stop there. They take the exposed email and password combinations and try them on Gmail, Facebook, PayPal, and bank login pages in a process called credential stuffing. Security researchers beleive that millions of successful account takeovers each year trace back to breaches at smaller, lower-profile services that users signed up for and forgot about. An old chess account could be the key that unlocks something far more valuable.
How Database Breaches Work
A database breach happens when an unauthorized party gains access to the server that stores a website's user records. This can happen through a software vulnerability, a stolen admin password, or a misconfigured server left open to the internet. Once inside, the attacker copies the database and either sells it, shares it on dark web forums, or uses it directly. In the Net-Chess case, the database appeared on a hacking forum where other criminals could download and exploit it freely.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to check whether your email address or password appeared in the Net-Chess breach or any other known data leak. The scan takes seconds and shows you exactly what information of yours has been found in the wild. Check your exposure for free today.
Breach Breakdown
39,745 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds