Chess.com, the leading online chess platform, has confirmed that an external system breach on June 5, 2025, resulted in unauthorized access to its user database.
The incident, discovered on June 19, 2025, impacted a total of 4,541 individuals, including one resident of Maine.
In response, Chess.com initiated its incident response protocols, engaged third-party cybersecurity experts to conduct a root cause analysis, and has offered affected users one year of identity theft protection services.https://cyberpress.org/iranian-cyber-attackers-breach-global-airlines/
Technical Overview and Notification Protocol
The breach occurred when threat actors exploited a vulnerability in Chess.com’s externally facing infrastructure, gaining illicit entry to servers containing personally identifiable information (PII).
The compromised data consisted of user names combined with other personal identifiers, though no financial or payment data were exposed.
Chess.com’s legal and security teams implemented containment measures and conducted a forensic investigation to determine the full scope of the hack.
Following industry best practices and Maine’s data security statute, Chess.com’s Head of Legal Department, Elias Colabelli, submitted a formal notification to the Maine Attorney General’s office on September 3, 2025.
This written notice followed the entity’s prompt discovery protocol and included a copy of the consumer notification template used for Maine residents, accessible via the state’s breach viewer system.
Because fewer than 1,000 Maine residents were affected, notifications to consumer reporting agencies were not required under state law.
Chess.com provided the following key details in its notification:
- Type of Organization: Other Commercial
- Entity Name: Chess.com, LLC
- Location: 877 E 1200 S #970397, Orem, UT 84097
- Notification Method: Written consumer notification delivered via postal mail
- Identity Theft Protection: Twelve months of coverage through a specialized provider, including credit monitoring, fraud resolution support, and dark web surveillance
The company has emphasized that all passwords in its system are hashed and salted using robust cryptographic algorithms, ensuring that even if hashed credentials were acquired, they would remain computationally infeasible to reverse.
Chess.com also reinforced its multi-factor authentication (MFA) requirements to minimize future unauthorized access risks.
In addition to consumer notifications, Chess.com’s executive leadership has strengthened its cybersecurity posture by:
- Performing a comprehensive vulnerability assessment across its network perimeter
- Upgrading firewall rulesets and intrusion detection systems (IDS)
- Implementing continuous security monitoring and threat intelligence feeds
- Conducting user awareness training focused on phishing and social engineering
While there is no evidence of subsequent unauthorized activity related to this incident, Chess.com continues to partner with cybersecurity consultants to validate the efficacy of its remediation efforts.
Affected users are encouraged to remain vigilant, update their account credentials, and enroll in the offered identity protection services to guard against potential misuse of their personal information.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates