国际象棋在线平台Chess.com遭遇大规模数据泄露事件1。泄露的733万多条用户记录包含用户名、邮箱、真名、国家、象棋等级分及谷歌广告管理器受众标签等38个数据字段1,总计15.5GB1。泄露数据中不包含密码、密码哈希或支付信息1。
发布者账户V0idix免费公开了这些数据,未提出勒索要求1。技术分析表明,数据系通过爬取网站而非利用系统漏洞获得1。这些记录跨越九个连续日期分批收集,其中约7.4%的记录出现重复1。研究人员通过验证200,000条样本记录的UUID版本1时间戳与注册日期的匹配情况,确认了100%的准确率1。
此次泄露与Chess.com在2023年经历的一起类似事件采用相同手法1。2023年那次泄露涉及82.8万条记录,同样通过爬取方式获得1;本次事件规模约为其9倍1。对于2023年的泄露,Chess.com曾声明"这不是数据破绽。我们的基础设施、成员账户和密码是安全的"1。
A massive data exposure has compromised over 7.3 million user accounts at Chess.com, the international chess platform.1 The leaked dataset contains 7,337,395 user records totaling 15.5 GB, including usernames, email addresses, real names, countries, locations, chess ratings, subscription status, and Google Ads Manager audience tags across 38 data fields.1 The exposure notably does not include passwords, password hashes, or payment information.1
Technical analysis indicates the data was obtained through web scraping rather than a direct system vulnerability.1 The records were collected across nine consecutive days in batches, with approximately 7.4% of entries appearing as duplicates.1 Verification of 200,000 sample records using UUID version 1 timestamps confirmed a 100% match rate with user registration dates.1 An account named V0idix released the data publicly without ransom demands.1
This incident mirrors a similar scraping incident in 2023, which exposed 828,000 records through identical techniques.1 The current leak is approximately nine times larger than the previous incident.1 Chess.com responded to the 2023 scraping incident by stating, "This is not a data breach. Our infrastructure, member accounts and passwords are secure."1
评论
还没有评论,欢迎留下第一条。