On Sunday a woman in Ohio got an email from Have I Been Pwned telling her that her address was in a Chess.com leak. She plays a few games on her lunch break under a username nobody at work knows. Now a file that anyone can download for free pairs that username with her real name, her country, her email address and the fact that she pays for a Diamond membership. Nothing has been stolen from her yet. But the next email that says “Chess.com: confirm your account” will know all four of those things, and that is what makes it work.
Confirmation: reported by Security Affairs, Techlicious and Hackread, and loaded into Have I Been Pwned on 13 September 2026 as verified. Not confirmed by the company: Chess.com had not issued a statement about the 2026 file at the time of writing.
What happened
A 15.5 GB file containing 7,337,395 Chess.com user records was posted free of charge on two data-leak forums on 12 August 2026, and Have I Been Pwned added it on 13 September 2026 with 4,653,212 unique email addresses. The poster, using the handle V0idix, asked for nothing in return; the file was then shared on through Telegram, according to Security Affairs and Techlicious, both reporting on 14 August.
The evidence points to scraping rather than a break-in. Security Affairs decoded the UUIDs in 200,000 sample rows and matched every one of them against registration dates; the records were “stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job,” and about 7.4% of accounts appear twice, revisited on different days. Have I Been Pwned adds a second signal: 99% of the email addresses had already appeared in earlier breaches, which is what a scrape of existing public and semi-public data looks like.
It is not a purely public scrape, though. Every row carries an advertising-audience segment label, which Chess.com’s public API does not hand out. Security Affairs concludes this “suggests an authenticated or internal-facing endpoint rather than the open developer API.” Chess.com had a similar incident in 2023, when its find-friends feature was abused to match externally sourced email addresses to accounts; the company said then that “this was NOT a data breach,” and the 2026 file is the same technique at roughly nine times the scale.
Chess.com has not confirmed the 2026 leak. A thread on its own forum has no staff statement in it.
What was exposed
No passwords or password hashes were in the file. Everything else that makes a phishing email convincing was. From the reporting and the HIBP data classes:
- Email address, 4.6 million of them. The delivery address for the follow-up scam.
- Username and user ID, and full or partial real name. A message that opens with your real name and your handle reads as genuine.
- Country and location. Enough to time the message to your morning and write it in your language.
- Rating, membership tier, account creation date and last login. “Your Diamond membership payment failed” is a much better lure when you actually have a Diamond membership.
- Advertising-audience segment labels. The promotional groups Chess.com had sorted you into. Useful mainly as evidence of how the data was pulled, but it is also a small portrait of how you were being marketed to.
Because there is no password, nobody can walk into your Chess.com account from this file alone. The risk is what people do with a name, a handle and an address: an email dressed as Chess.com, a password-reset lure, or a match against older leaks that did carry a password, which for 99% of these addresses already exist.
What to do now
Most of this has nothing to do with OptMsg, and the first two steps take five minutes.
1. Assume any “Chess.com” email is a test until proven otherwise. Expect “unusual login,” “your subscription could not be renewed,” “claim your rating badge,” or “verify your account after the recent leak.” Do not click login links inside them. Open chess.com yourself and check there. 2. Change your Chess.com password anyway, and make it unique. The file has no passwords, but older leaks may, and 99% of these addresses have been in one. A password manager makes this a two-minute job and gives every account its own password. 3. Check what Chess.com offers for sign-in. Techlicious notes the platform has not offered two-factor authentication, quoting its past position that “there is nothing so personal and sensitive that needs that level of protection.” If that has changed by the time you read this, turn it on; if not, a unique password is your whole defence there. 4. Turn on the strongest sign-in your email account offers. Your email is how most accounts get reset. A passkey where available, an authenticator app otherwise. This is the step that matters most and it is not about chess. 5. Search your address at Have I Been Pwned. It will show you which earlier breaches this address is in, which is your list of other accounts to fix. 6. If your username was private to you, treat it as public now. If you used the same handle on other sites, a scammer can connect them.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this. The data was pulled from Chess.com’s side, and your address was one of 4.6 million in the file. What an opt-in inbox changes is where the follow-up lands.
Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the “verify your account” email from a look-alike domain the real Chess.com has not used lands in Trash, where you are not reading it half-asleep with your real name and rating quoted back at you. The genuine Chess.com reaches your Inbox once you approve it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a genuine notice is not lost.
The password point is worth one sentence here even though no password leaked, because for most of these addresses an older leak already supplied one. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. The pair of your address and some 2019 password opens nothing at OptMsg, and the reset route into your other accounts stays shut.
What that does not cover: a phishing page you open yourself, a message from a sender you did approve whose own account was taken, a compromised device, or someone with your unlocked phone. Those are the steps above, and the first one does most of the work.
If you want the next leak’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read why your inbox should not care about a leaked password.
Ready for an inbox that stays quiet after a breach? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
How do I know if I am in the Chess.com data breach? Search your email address at Have I Been Pwned. The Chess.com (2026) entry was added on 13 September 2026 with 4,653,212 email addresses. If you subscribe to HIBP notifications, you will have received an email.
Was Chess.com hacked? The evidence points to scraping, not a break-in: the records were collected in daily batches over nine days, and 99% of the email addresses were already in earlier breaches. The ad-segment labels on every row suggest an authenticated or internal-facing endpoint was used. Chess.com has not confirmed or explained the incident.
Were passwords leaked in the Chess.com breach? No. No passwords or password hashes were found in the file. Email addresses, usernames, real names, countries, ratings, membership tiers and advertising segments were.
What should I do if my Chess.com account is in the leak? Treat any email claiming to be from Chess.com as suspect and sign in directly instead of through a link. Set a unique password on Chess.com and on your email account, and turn on the strongest sign-in your email provider offers.
Would OptMsg have stopped this? No. The data was taken from Chess.com. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.
Sources
- Have I Been Pwned: Chess.com (2026) — added 13 September 2026
- Security Affairs: Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping — 14 August 2026
- Techlicious: Chess.com data leak puts 7 million players in check — 14 August 2026
- Hackread: Hacker Leaks 7 Million Scraped Chess.com User Records — August 2026