Online chess giant Chess.com has disclosed a data breach that compromised the personal information of 4,541 people (according to a filing with the Maine Attorney General's Office).

The cybersecurity incident occurred on June 5, 2025, and was discovered almost two weeks later, on June 19, 2025. Chess.com confirmed that the breach was the result of an external attack, where attackers gained unauthorized access to sensitive data.
Chess.com: Data Breach
The company said the hackers were able to obtain names and personal identifiers, though it did not provide a full breakdown of all the data exposed. The breach affected users in multiple regions, including a Maine resident.
See also: Texas sues PowerSchool over student data breach
Chess.com began notifying affected individuals via written notices on September 3, 2025. To help protect its community, the company is offering protection services identity theft.
The notice was officially submitted by Elias Colabelli, Head of Legal and Data Protection Officer at Chess.com, who stressed that the company is strengthening its systems to prevent similar incidents in the future.
While the number of affected users may seem low compared to other large-scale data breaches, the incident highlights how even large online platforms remain targets for cybercriminals. With more than 150 million users worldwide, Chess.com holds a huge amount of personal data, making it an attractive target for hackers.

Cybersecurity experts warn that breaches of this nature can pave the way for identity theft, phishing attempts , and further fraud if the stolen data is circulated on underground markets. Chess.com has not yet disclosed whether law enforcement is involved in the investigation.
See also: Bridgestone: Cyberattack affects production
The company says it continues to work to strengthen security protocols and closely monitor its systems. For users, the breach is a reminder to remain vigilant, monitor financial accounts , and be wary of suspicious emails that could exploit stolen personal information.
The Chess.com data breach is a special case that deserves comment, not so much for the number of users affected, but for what it represents. On the surface, it may seem “insignificant” to expose the data of a few thousand people on a chess-related platform. However, the incident demonstrates in the clearest way that no organization, no matter how “innocent” or non-commercial it may seem, is safe from risk in today’s digital landscape.
Chess.com is not just a gaming website; it is a global community of hundreds of millions of people, with built-in social networking features, premium memberships, and even high-level tournaments. This means it has vast amounts of personal and financial data, making it a goldmine for cybercriminals. So the breach, however small, is a wake-up call: hackers don’t discriminate based on the nature of the platform, but rather on the value of the data they can extract.
See also: GhostRedirector hackers compromise Windows Servers with malicious IIS Module

Furthermore, the length of time it took for users to be notified—almost three months—raises questions about the company’s transparency and speed of response . In an era where phishing attacks can be launched within hours of a data breach, such a long delay leaves victims exposed without knowing they are at risk. The 12-month “identity protection package” offered is certainly an attempt at damage control, but it doesn’t negate the fact that data, once leaked, can never be retrieved.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The case also highlights a broader reality: cybersecurity on entertainment and education platforms can no longer be considered a secondary issue. As more services move online, attacks on “unexpected” targets will increase. For users, the lesson is clear: even if the service they use seems “innocent,” protecting passwords, using authentication , and being vigilant about suspicious emails should be standard practices.
