Chess.com scraping exposes 4.7 million email addresses
Data scrapers are putting the internet in checkmate.

Image by Cybernews.
- 4.7 million Chess.com email addresses were added to Have I Been Pwned after attackers scraped public-facing user data.
- The 15GB dataset included emails, usernames, names and countries, but no passwords or financial information.
- Troy Hunt says the data likely came from scraping rather than a system breach, with 99% of emails already appearing in previous breaches.
- The incident shows how public data can be combined into detailed profiles, giving scammers more information for targeted phishing attacks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A massive trove of Chess.com user data has landed in Have I Been Pwned after attackers scraped millions of public profiles, highlighting how much information can leak even when hackers never break into a company's systems.
Have I Been Pwned (HIBP) added the dataset to its database after it was reportedly posted on an underground forum in August. The dataset weighed more than 15GB and included email addresses, as well as usernames, names, countries, and other information linked to Chess.com accounts.
Crucially, no passwords, password hashes, or financial information was exposed.
According to an analysis by HIBP's Troy Hunt, the data appears to have been obtained through scraping rather than a systems breach. “When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory,” writes Hunt.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The distinction matters. Instead of breaching a company's defenses to steal hidden data, scraping involves using automated software to harvest information that is already visible to the public or accessible through public-facing features and APIs.
Even though no passwords were compromised, the resulting dataset can still create a security problem.
A username, location, and email address may not look especially sensitive on their own. However, when combined, they can give scammers useful details for targeted phishing campaigns.
As bad as a breach
This is not the first time Chess.com users have found their information in a large scraped dataset.
In November 2023, more than 800,000 Chess.com user records ended up on a cybercrime forum after an attacker scraped information from the platform. The information appeared to have been collected through Chess.com's API.
Large-scale scraping has repeatedly turned publicly available information into valuable datasets for criminals.
In 2025, attackers claimed to have scraped 1.2 billion Facebook user records, again by abusing one of the platform's APIs. A sample examined by researchers included user IDs, names, email addresses, usernames, phone numbers, locations, birthdays, and genders.
LinkedIn has faced an even longer-running problem with data scrapers. In 2021, a dataset containing information from 500 million LinkedIn profiles was offered for sale. The leaked sample included names, email addresses, phone numbers, workplaces, and other professional information.
The same year, another dataset containing information on 88,000 US business owners appeared online. This dataset included names, email addresses, locations, and other professional details, mostly of people who had recently changed jobs.
And it’s not just profile information that’s being scraped. In 2025, a service advertised access to 1.8 billion Discord messages belonging to 35 million users, along with 207 million voice sessions, user profiles, and data from thousands of servers.
These incidents show why the line between a breach and a scrape matters less to users than it might seem. Even when attackers never obtain passwords or break into a company's systems, they can still assemble detailed profiles from information scattered across the internet, which can help run sophisticated online scams.