A dataset allegedly sourced from Chess.com surfaced online in August 2026, containing roughly 7.3 million rows tied to 4.6 million unique email addresses. Alongside emails, the data included usernames, real names, countries, and other account-related details. Analysis indicated the information was likely harvested through scraping rather than a direct system compromise, a conclusion reinforced by the fact that 99% of the emails had already appeared in prior breaches.
While scraped data lacks passwords or credentials, the combination of emails, usernames, and names still provides useful material for phishing, credential-stuffing, and social-engineering campaigns. Reused identifiers across platforms can help attackers correlate identities and target users at other services, including corporate accounts.
What to take away: Even non-credential scrapes feed the broader identity-attack ecosystem. Organizations should reinforce phishing awareness and monitor for exposed employee emails that could be leveraged against enterprise identity systems.