Skip to content
Data breachResolved

Chess.com discloses data breach via compromised third-party file-transfer app

Chess.com began notifying about 4,500 users that their personal information was exposed after an external threat actor gained unauthorised access to a third-party file-transfer application the platform used.

Victim
Chess.com
records
4.5K
users
4.5K

On 3 September 2026, Chess.com โ€” the world's largest online chess platform, with well over 100 million registered members โ€” began notifying affected users of a data breach stemming from a compromised third-party file-transfer application it had used. The company said a total of 4,541 individuals worldwide had some personal information exposed, a figure it noted represented fewer than 0.003% of its user base.

According to the disclosure, Chess.com discovered the suspicious activity on 19 June 2026, after identifying anomalous access to data held in the external file-transfer tool. The subsequent investigation determined that an outside threat actor had reached the system on 5 June and again on 18 June, exfiltrating a limited set of records. The exposed data included users' names and additional personal identifiers; the company said no financial information was involved, and that its own infrastructure, source code and member-account systems were unaffected.

Contained to a third-party tool

Chess.com stressed that the incident was confined to a third-party application rather than its core platform, and that member passwords and account systems were not compromised. The company offered affected users two years of complimentary identity-theft protection and credit monitoring, with an enrolment deadline set for later in the year. Given the small number of individuals involved, the absence of financial or credential data, and the completion of the investigation and notifications, the incident was assessed as resolved โ€” a reminder that even security-conscious platforms inherit risk from the outside tools in their supply chain.

Timeline

  1. Chess.com discovers suspicious activity involving data stored in a third-party file-transfer application; investigation finds an external actor accessed the system on 5 June and again on 18 June.

  2. Chess.com begins mailing written breach notifications to the 4,541 individuals whose data was exposed, offering complimentary identity-theft and credit monitoring.

Sources

  1. cyberinsider.comhttps://cyberinsider.com/chess-com-discloses-data-breach-from-3rd-party-system-compromise/
  2. neowin.nethttps://www.neowin.net/news/chesscom-confirms-data-breach/
  3. threatlabsnews.xcitium.comhttps://threatlabsnews.xcitium.com/blog/chess-com-data-breach-third-party-file-transfer-app-compromise/

Related incidents