logo

Defending against database ransomware attacks

ID: 8f2eda66-baf4-5478-b483-55a0a2410574

STIX ID: report--8f2eda66-baf4-5478-b483-55a0a2410574

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2025-10-06

Date Updated: 2026-05-01

...
...

This report details the rise of "malware-less" database ransomware campaigns in which automated bots scan the Internet for exposed or misconfigured database instances, authenticate via weak/default credentials, copy or delete data using native DB commands, and leave ransom notes or threaten data leaks. It describes commonly targeted systems (MongoDB, PostgreSQL, MySQL, Redis), typical attack flow and indicators (newly created README/RECOVER tables or collections), and recommends network segregation, strong authentication, backups, continuous scanning for exposures and IOCs, and detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.