// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / Chess.com (2026)
Breach Record

Chess.com (2026)

DISCLOSED 2026-08-03 · STOLEN CREDS · 4,653,212 RECORDS EXPOSED

In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared...

The record

What we know

Disclosed
2026-08-03
Attack vector
Stolen Creds
Records exposed
4,653,212
Domain
chess.com
Data classes exposed
Email addressesGeographic locationsNamesUsernames
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Chess.com (2026) disclosure. It updates if new public reporting emerges. All tracked breaches →

Chess.com (2026) just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →