Major arcade game maker leaks nearly 19 million user records, ranging from full names to unique IDs

On March 19th, the Cybernews team discovered three exposed servers containing data for Wahlap users. Wahlap is a China-based arcade maker, one of the largest in the world, partnering with gaming giants such as Sega, Warehouse of Games, Timezone, and others. 

Here are the key findings:

  • In total, 18.9 million records were left exposed online, covering Wahlap members’ identifiers, gaming behavior data, asset information, customer snapshots, and application logs. 
  • According to our team, the data most likely leaked via Wahlap’s WeChat mini programs. WeChat mini programs are lightweight applications that run inside the WeChat ecosystem. 
  • The exposed information can be broadly put into five index categories: Wahlap members data, members’ gaming behavior data, Wahlap asset data, consumer snapshot data, and other indices.

We have reached out to Wahlap and will update this article once we receive a reply. Several days after the discovery, the team noticed that the exposed cluster was no longer publicly accessible.

For more information, here’s the full report: https://cybernews.com/security/wahlap-arcade-game-maker-data-leak-wechat

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading