logo

Hackers exploit unsecured MongoDB instances to wipe data and demand ransom

ID: 6e3e2d4e-8718-5203-b810-034538989ac9

STIX ID: report--6e3e2d4e-8718-5203-b810-034538989ac9

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Security firm Flare reports attackers have hijacked and wiped at least 1,416 unsecured MongoDB servers (of 3,100 fully exposed), replacing data with ransom notes demanding about $500 in Bitcoin; one Bitcoin address appears in >98% of cases, suggesting a single dominant actor. The report emphasizes that widespread misconfiguration — not active software RCE exploitation — is enabling this large-scale, low-complexity but high-impact campaign and urges applying hardening and prevention best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.