CyberSecurity SEE

Chess.com Data Breach Exposes 7.3 Million Users Through Scraping

Chess.com Data Breach Exposes 7.3 Million Users Through Scraping

Data Breach of Chess.com: 7.3 Million User Profiles Compromised

In a staggering revelation, over 7.3 million user profiles from Chess.com have leaked onto various data leak forums, prompting significant concern among the user base. The dataset, amounting to a hefty 15.5 GB, has been made freely available by an individual specializing in distributing scraped databases. It contains sensitive information that includes not only email addresses and usernames but also real names, geographical locations, chess ratings, and details on subscription tiers. Additionally, internal marketing segmentation fields derived from Google Ad Manager are present within this trove of data.

While Chess.com has yet to officially confirm whether the exposed data stems from a breach of their internal systems or if it results from the misuse of platform features, experts are leaning toward the latter scenario as the more plausible explanation. A series of technical analyses conducted by cybersecurity researchers has confirmed the authenticity of the data, with verification processes revealing that timestamps embedded in account identifiers closely align with the actual registration dates of the accounts. This was demonstrated through rigorous testing of 200,000 sample records, which indicated a perfect 100% correlation—an impressive feat that would be virtually impossible without legitimate access to Chess.com-issued identifiers that are accurate to the millisecond.

A closer examination of the incident reveals three defining characteristics that suggest systematic scraping rather than a conventional database breach scenario. The data was compiled over nine consecutive days in daily batches, contradicting the common practice of extracting data in a single operation. Moreover, around 7.4% of user records appear twice, yet show differing timestamps, a pattern atypical of standard database exports. Notably, this dataset exhibits a striking resemblance to a prior incident in November 2023, which affected approximately 828,000 Chess.com users. During that incident, the company asserted that no breach occurred but rather that attackers had exploited the find-friends feature by cross-referencing external email lists against existing accounts.

However, complications arise when considering that each record includes Google Ad Manager audience segment data, encompassing coach-nudge experiment groups, trial eligibility flags, lapsed-user cohorts, and targeting information tied to user rating bands. Such marketing aspects notably do not appear within the public API of Chess.com, implying that the entity responsible for the data collection may have accessed either an authenticated or internal endpoint, rather than merely relying on publicly available developer tools. This particular discrepancy introduces a critical question that Chess.com must address: how exactly was the data acquired?

While the absence of passwords in this leaked dataset may relieve some immediate security concerns, the combination of verified email addresses alongside real names, locations, skill ratings, and subscription statuses still poses significant risks. Users may find themselves vulnerable to targeted phishing campaigns crafted from this detailed information. Consequently, it is advisable for Chess.com users to exercise increased caution regarding unexpected emails from the platform, especially those related to membership renewals or fairness disputes.

In the broader context, the prevailing long-term risk revolves around credential reuse. Users who often recycle the same email and password combinations across various services might be in jeopardy if those credentials were compromised elsewhere. Therefore, it is imperative for individuals to adopt unique passwords for different accounts to enhance their security posture.

The importance of addressing this incident cannot be overstated. As Chess.com works to uncover the full scope of this leak and inform those affected, users are encouraged to remain vigilant, update their security practices, and be wary of any unsolicited communications that may exploit this unfortunate data exposure.

The incident serves as a stark reminder of the vulnerabilities that can arise in our increasingly digital lives, underscoring the need for ongoing awareness and proactive measures in safeguarding personal information against potential breaches.

For a more in-depth exploration of the situation, visit Security Affairs.

Source link

Exit mobile version