The app’s website exposed a link to an API endpoint that was left without a password, allowing third-parties to obtain passwords for admin accounts.
Article Link: https://www.zdnet.com/article/netanyahus-party-exposes-data-on-over-6-4-million-israelis/#ftag=RSSbaffb68