MongoDB is once again experiencing problems with its databases as various data appears to have been leaked.

In February, a security researcher named Bob Diachenko found a MongoDB database containing four data collections and a total of 150GB of data, including about 763 million unique emails. The data instance was completely accessible and the data was stored in plain text. The occasional personally identifiable information (PII) is the latest MongoDB database to be hit in a breach totaling millions of records.
In a blog post announcing the discovery, Diachenko detailed the type of data found in the files, as well as the owner of the database – Verifications.io. When informed of the availability of the dataset, the company quickly took down the website, but even as of this writing, the site is not online.
While the data exposed in this incident is notable for its size, it is just the latest in a significant series of data breaches and exposures involving MongoDB. In a blog post at Krebs Security, Brian Krebs reported that tens of thousands of MongoDB databases had been hit with ransomware. These databases that did not use authentication checks were particularly vulnerable to ransomware attacks.
Also in January, Diachenko discovered another open MongoDB database filled with personal information from job seekers. It's probably very easy to configure a MongoDB database in ways that open the door to thieves and attackers.
And that’s really the point. MongoDB can be configured in ways that are quite secure, but a novice developer who simply takes the default settings at every step of creating a database will create a data set with no protection whatsoever. The number of MongoDB instances that are likely to be compromised is very large. A quick Shodan search shows 67,864 MongoDB installations worldwide, with the majority – just over two-thirds – in the US. China is next in terms of MongoDB usage, with just under half the number of instances found in the US.
MongoDB is also popular in the cloud. The same Shodan search shows that Amazon.com has 9,016 MongoDB instances, Digital Ocean has 4,966, Tencent hosts 3,918, Microsoft Azure has 2,849, and Google Cloud has 1,931.
What should be done to secure MongoDB databases? The most immediate answer would be to change the default settings, but MongoDB’s status as an open source project makes the process slow at best. The answer, instead, lies in training the administrators and developers who are most likely to deploy MongoDB on their own. As Chris DeRamus, CTO of DivvyCloud, wrote to Dark Reading in a statement: “We live in a world where data is king – collecting, storing, and leveraging data is essential to running every kind of business you can think of. There are many reasons why organizations should be diligent about ensuring data is protected with the right security controls.”
MongoDB lists companies like KPMG, Telefonica, and Eharmony as its customers. Apparently it is possible to configure and manage a MongoDB database in a secure and regulatory compliant manner.
