Skip to main content

Chess.com (2026) data breach

The Chess.com (2026) breach happened on August 3, 2026 and exposed 4,653,212 accounts. 4 kinds of data were exposed.

Overview

Site
chess.com
Breach date
August 3, 2026
Recorded on
September 13, 2026
Accounts exposed
4,653,212
Exposed data
Email addresses, Geographic locations, Names, Usernames
Risk score
25 out of 100

Risk based on the exposed data

This breach scores 25 out of 100. The score is driven mostly by Email addresses, Names, Geographic locations.

The risk score is a guide to how dangerous a breach is, judged by the kinds of data exposed. The number of accounts is not included.

Breaches from the same period

  • Questel (2026-08-01, 1,226,209 accounts)
  • CyrusOne (2026-08-05, 373,460 accounts)
  • Alcon (2026-08-01, 218,395 accounts)

What affected users should do

  • Passwords were not exposed, but you may receive fake emails aimed at the exposed email addresses.
  • Turn on two-factor authentication for your login.

Create a new password →

This site organizes publicly available information about data breaches. Data as of October 7, 2026. Breach dates are as originally listed; when only the month is known, the date is recorded as the 1st.