Top arcade game maker leaks nearly 19 million user records via WeChat mini app



  • Wahlap left open an Elasticsearch instance that exposes 18.9 million records linked to its WeChat mini-program ecosystem.
  • The data included 6.6 million unique union IDs, 1.7 million phone numbers, and personal data that could enable targeted phishing and fraud.
  • The file was locked after its disclosure, although there is no evidence that the exposed information was exfiltrated.

Wahlap, the Chinese video game maker, allegedly kept a huge user database open on the Internet, available to anyone who knew where to look, according to security researchers from cyber news have warned, putting personal information at risk.

Wahlap is one of the largest arcade game manufacturers in the world and works with some of the biggest names in the gaming industry, such as Sega or Timezone. It offers Wahlap WeChat mini programs, lightweight applications that run within the WeChat ecosystem.

Leave a Comment

Your email address will not be published. Required fields are marked *