Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Wahlap data leak exposes 18.9 million records from WeChat mini-program ecosystem

A misconfigured Elasticsearch instance belonging to Wahlap exposed 18.9 million user records, including unique Union IDs, phone numbers, and personal details, creating a significant risk for targeted phishing and fraud campaigns. The database was left publicly accessible without authentication, allowing potential unauthorized access. While no evidence of data exfiltration was found and the instance was secured after disclosure, the incident underscores the critical risk of unsecured cloud data stores.
Read Full Article →

Data Security Wahlap data leak exposes 18.9 million records from WeChat mini-program ecosystem May 21, 2026 Share By SC Staff (Adobe Stock) Chinese arcade game maker Wahlap reportedly left a massive user database exposed online, containing 18.9 million records tied to its WeChat mini-program ecosystem. The data, which included unique Union IDs, phone numbers, and personal details, could have been exploited for targeted phishing and fraud, with further coverage provided by Tech Radar. Security researchers from Cybernews discovered an open Elasticsearch instance belonging to Wahlap, a prominent arcade game manufacturer that collaborates with industry giants like Sega. The exposed data encompassed 6.6 million unique Union IDs, 1.7 million phone numbers, and personal information such as dates of birth and full names. This information could be used to profile Wahlap users and facilitate sophisticated phishing attacks and fraudulent activities. Researchers found no evidence of data exfiltration and the database was secured shortly after the disclosure. The incident highlights the potential risks associated with storing sensitive user data in unsecured cloud environments. Source: Tech Radar SC Staff Related Data Security Carding forum B1ack’s Stash releases millions of stolen credit card records SC Staff May 20, 2026 The released data is unusually comprehensive, including full card numbers, expiration dates, CVV2 codes, cardholder names, billing addresses, email addresses, phone numbers, and IP addresses. Data Security Trump Mobile phone provider reportedly leaking customer data SC Staff May 20, 2026 A pair of YouTubers say their personal information, including mailing and email addresses, was leaked after they purchased the Trump Mobile T1 phone. Encryption Discord implements end-to-end encryption for voice and video calls SC Staff May 20, 2026 The popular platform, which serves an estimated 690 million registered users, extended its open-source DAVE encryption protocol to cover all its clients, including desktop, mobile, web browsers, and gaming consoles. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bit Block Cipher Cipher Ciphertext Cryptographic Algorithm or Hash Cryptographic Hash Functions Data Loss Prevention (DLP) Digital Envelope Digital Signature Digital Signature Standard (DSS) You can skip this ad in 5 seconds

Share this article