22,900 MongoDB Databases Affected in Ransomware Attack

An attacker scanned for databases misconfigured to expose information and wiped the data, leaving a ransom note behind.

Dark Reading Staff, Dark Reading

July 3, 2020

1 Min Read
Dark Reading logo in a gray background | Dark Reading

Nearly 23,000 MongoDB databases are affected in a ransomware campaign designed to wipe information from misconfigured databases lacking password protection, ZDNet reports.

The attacker reportedly used an automated script to scan for exposed databases. When it found one, the script deleted the contents and uploaded a ransom note demanding 0.015 bitcoin to retrieve them. If the victim doesn't pay in two days, the attacker threatens to publish their information and report them to their local GDPR enforcement authority, the report states. 

This attack is the latest in a series of incidents conducted by attackers who profit from wiping exposed MongoDB databases and demanding ransom. In January 2017, a cluster of attacks against MongoDB servers affected more than half of Internet-facing MongoDB databases. Unprotected MongoDB databases have been a source of multiple leaks and breaches, including last year's attack on Choice Hotels and a massive exposure of 763 million email addresses.

Security admins worried about protecting their assets can consult MongoDB's Security Checklist, which contains a list of steps to better protect databases. 

Read more details here.

_OMDIA_LOGO_Endorsement_Black.png

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights