Chess.com Data Breach: 4,500 Users Affected
- Chess.com, the world's largest online chess platform, experienced a data breach in September 2024.
- Chess.com, founded in 2005, hosts approximately 10 million games daily and serves more than 100 million registered users as reported by Chess.com.
- While the full extent of the compromised data is still being assessed, Chess.com has indicated that the breach involved user information.
Chess.com Data Breach Exposes Data of Over 100 Million Users
Table of Contents
Published September 4, 2024, at 19:10:54 UTC. Updated as new information becomes available.
What Happened?
Chess.com, the world’s largest online chess platform, experienced a data breach in September 2024. Hackers gained access to customer information through a file transfer tool used by the company. The breach potentially compromised the data of over 100 million registered users.
Chess.com, founded in 2005, hosts approximately 10 million games daily and serves more than 100 million registered users as reported by Chess.com. The company has not yet publicly disclosed the specific file transfer tool exploited in the attack.
What Data Was Compromised?
While the full extent of the compromised data is still being assessed, Chess.com has indicated that the breach involved user information. The company has not specified exactly *what* information was accessed, but breach notifications submitted to regulators suggest it could include usernames, email addresses, passwords (hashed), and potentially other account details according to TechCrunch.
Chess.com has stated that it has “no indication that any of your impacted data has been shared publicly on any online sources,” but advises users to remain vigilant.
Who is Affected?
All Chess.com users who had an account prior to the breach are potentially affected. With over 100 million registered users, this represents a notable number of individuals. Users who reused their Chess.com password on other websites are at increased risk.
| User Category | Risk Level | Recommended Action |
|---|---|---|
| All Chess.com Users | Moderate | Change password immediately. Enable two-factor authentication. |
| Users Reusing Passwords | High | Change passwords on *all* accounts using the same credentials. Monitor accounts for suspicious activity. |
| Users with Sensitive Information | High | Be extra vigilant for phishing attempts. Consider credit monitoring. |
Timeline of Events
- September 2024: Chess.com detects and responds to the data breach.
- September 3,2024: news of the breach begins to surface in media reports (TechCrunch).
- September 4, 2024: Chess.com begins notifying affected users.
- Ongoing: Investigation and remediation efforts continue.
What Should You Do?
Chess.com recommends the following steps for affected users:
- Change your password: Create a strong, unique password that you do not use on any other websites.
- Enable two-factor authentication (
