logo

Exposed MongoDB instances still targeted in data extortion attacks

ID: 8d3da07e-013f-50c1-8ae3-e91677f7c631

STIX ID: report--8d3da07e-013f-50c1-8ae3-e91677f7c631

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-02-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed an automated extortion campaign targeting misconfigured, publicly exposed MongoDB instances: attackers accessed unsecured databases (approximately 3,100 without authentication), wiped or removed data on many (~45.6% of unrestricted instances, roughly 1,400 compromised), and left ransom notes demanding ~0.005 BTC (~$500), with most notes directing payments to one of five wallet addresses—suggesting a focused criminal operator exploiting poor authentication, outdated software, and exposed deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.