• Wahlap left an open Elasticsearch instance exposing 18.9 million records tied to its WeChat mini‑program ecosystem
  • Data included 6.6 million unique Union IDs, 1.7 million phone numbers, and personal details that could enable targeted phishing and fraud
  • The archive was locked down after disclosure, though there’s no evidence the exposed information was exfiltrated

Chinese arcade-maker powerhouse Wahlap, reportedly kept a huge user database open on the internet, available to anyone who knew where to look, security researchers from Cybernews have warned, putting personal information at risk.

Wahlap is one of the largest arcade makers in the world, working with some of the biggest names in the gaming industry, such as Sega, or Timezone. It offers Wahlap WeChat mini programs, lightweight applications that run inside the WeChat ecosystem.



Source link