Threat actors are actively targeting unsecured MongoDB databases in automated data extortion attacks, demanding low ransoms from owners to restore their compromised data, with further coverage provided by Bleeping Computer.The attacks exploit misconfigured MongoDB instances accessible without restriction. Researchers from Flare discovered over 208,500 publicly exposed MongoDB servers, with nearly half of those lacking authentication already compromised. The attacker wipes the data and leaves a ransom note, typically demanding 0.005 Bitcoin (approximately $500-$600) within 48 hours for data restoration. Analysis indicates a single threat actor is responsible, using a prevalent Bitcoin wallet address across most ransom notes. Many remaining exposed instances may have already paid a ransom. Additionally, a significant number of exposed servers run older, vulnerable versions, though these are primarily susceptible to denial-of-service attacks rather than remote code execution.These attacks highlight the critical need for robust database security practices, including avoiding public exposure unless necessary, implementing strong authentication, and enforcing strict network access controls. Regular updates to MongoDB and continuous monitoring for exposure are essential. The lack of guaranteed data recovery after payment underscores the risks associated with these extortion schemes, emphasizing the importance of proactive security measures to prevent such incidents.Source: Bleeping Computer
Data Security, Patch/Configuration Management
Automated extortion attacks target exposed MongoDB instances

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



