Chess.com disclosed a data breach affecting 4,541 individuals, arising from compromise of a third-party file transfer application, with attackers maintaining access between 5 and 18 June 2025.
The Corpus Has A Size Bias And Should Say So
This database is assembled from what gets reported, and what gets reported skews large. Four and a half thousand people is small enough that most breach compilations will not mention it.
That is a selection problem of the kind filed at 25-1225. If the corpus only records incidents above an implicit size threshold, its picture of how organisations are compromised is drawn from large organisations — and the techniques recorded here may not be the ones that dominate by count.
The Vector Is The Same One, Again
Managed file transfer, for the third time this year in this corpus: Western Alliance at 25-0214, the Cl0p Oracle campaign at 25-1007, and now a consumer platform with a four-figure affected count.
The argument at 25-0214 holds regardless of victim size. These products are internet-facing because that is their function, authenticate external parties because that is how they work, and hold precisely the files an organisation considered too large or too sensitive for email.
Thirteen Days, And A Precise Figure
A defined access window and an exact affected count is better documentation than most eight-figure incidents in this database provide.
The corpus filed at 25-0717 that reachable, taken and published are three different populations and that most disclosures do not say which they mean. A figure of 4,541 with a thirteen-day window suggests somebody established what was actually accessed. That is the exception, and it is easier at this scale.
Compiled from public reporting and company disclosure, listed below. Corrections: corrections@forensicpost.com.