Top arcade game maker leaks nearly 19 million user records via WeChat mini app
Date:
Thu, 21 May 2026 15:05:00 +0000
Description:
Researchers found a new Elasticsearch instance containing plenty of sensitive data.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Wahlap left an open Elasticsearch instance exposing 18.9 million records tied to its WeChat miniprogram ecosystem Data included 6.6 million unique Union IDs, 1.7 million phone numbers, and personal details that could enable targeted phishing and fraud The archive was locked down after disclosure, though theres no evidence the exposed information was exfiltrated Chinese arcade-maker powerhouse Wahlap, reportedly kept a huge user database open on the internet, available to anyone who knew where to look, security researchers from Cybernews have warned, putting personal information at risk.
Wahlap is one of the largest arcade makers in the world, working with some of the biggest names in the gaming industry, such as Sega, or Timezone. It
offers Wahlap WeChat mini programs, lightweight applications that run inside the WeChat ecosystem. For those unfamiliar with WeChat, it is one of the most popular mobile apps in the Chinese market. It is primarily a chat app, but offers all sorts of features from instant payments to, apparently,
lightweight gaming. These features come in the form of mini apps displayed within WeChat, and Wahlap seems to have gathered and stored the generated
data in an open Elasticsearch instance. Latest Videos From You may like Messaging app Tokee may have leaked 1.2 million user profiles Top Android AI photo and video editor exposes nearly two million user images and videos Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram Risk of phishing and fraud The Cybernews team split the information into multiple categories: Wahlap member data, gaming behavior data, asset data, consumer snapshots, and other indices.
In total, 18.9 million records were exposed online, with the Wahlap member data category being by far the biggest. Weighing over 10GB, it contains 6.6M unique Union IDs, 1.7M unique phone numbers, and 24k dates of birth and full names.
The researchers believe that the data could have been used to profile Wahlap users and target them with highly personalized phishing attacks and fraud. Additionally, the records contained data that revealed user IDs within the Wahlap ecosystem referring to different available mini programs as well as registration dates for specific games, the Cybernews team said. This is precisely the kind of information that threat actors can use to sound credible.
However, there is no evidence that the data had been exfiltrated already. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro
newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Cybernews reached out to Wahlap, and while it didnt receive a written confirmation or acknowledgement, it did notice that the archive was locked down soon after. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/top-arcade-game-maker-leaks-nearly-19-m illion-user-records-via-wechat-mini-app
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)