HomeSecurityNew wave of extortion attacks targeting exposed MongoDB databases

New wave of extortion attacks targeting exposed MongoDB databases

A familiar but persistent phenomenon is making a comeback in cybersecurity, with a threat actor systematically targeting exposed MongoDB databases through automated extortion attacks. The tactic relies not on sophisticated exploits or zero-day vulnerabilities, but on a perennial problem: misconfiguration of systems that are left open to the internet without basic protection mechanisms.

MongoDB

The easy target: Databases without access control

The attacker is exclusively targeting MongoDB instances that are accessible without authentication. These are cases where administrators have left the databases exposed, either through negligence or a lack of understanding of security settings. According to available data, about 1,400 servers have already been compromised, with data deleted and replaced with a ransom note.

See also: Why people still fall for phishing in 2026

The amount demanded is relatively low by ransomware standards: around 0.005 Bitcoin, or $500–600. The low price seems to be a conscious choice, increasing the chances of payment from smaller businesses or independent administrators.

An old practice that never disappeared

These types of attacks are not new. By 2021, there had been massive waves of them deleting thousands of MongoDB databases, often with ransom demands for the “restore” of the data. In some cases, the attackers didn’t even ask for money, limiting themselves to completely destroying the databases.

Although the intensity of the attacks appeared to be decreasing in recent years, new findings show that the phenomenon has not been eliminated, it simply continues on a smaller, but steady, scale.

See also: Chrome extensions abuse links and steal access to ChatGPT

New wave of extortion attacks targeting exposed MongoDB databases

What Flare's research revealed

Researchers at cybersecurity firm Flare conducted a pentesting exercise and identified more than 208,500 publicly exposed MongoDB servers worldwide. Of these, approximately 100,000 were revealing operational information, while 3,100 were fully accessible without any form of authentication.

Even more worrying is the fact that almost 45.6% of these open servers had already been compromised at the time of analysis. The databases had been deleted and in their place was a ransom note with a strict 48-hour payment deadline.

Low ransoms, zero guarantees

Analysis of the ransom notes showed that almost all of the demands asked for the same amount: 0.005 BTC. Flare points out that, despite the attackers' promises of data recovery, there is no guarantee that the data has been preserved or that it will be returned after payment.

Indicative of the “industrial” nature of the attack is the fact that only five different Bitcoin addresses, with one of them being used in 98% of cases. This indicates a single threat actor or an extremely limited group.

Old versions and additional risks

In addition to the lack of access control, Flare found that nearly 95,000 exposed MongoDB servers are running older versions of the software, vulnerable to known n-day vulnerabilities. While most of these flaws are limited to denial-of-service attacks and do not allow remote code execution, they do create a high-risk environment.

See also: Hackers breached 200+ sites via Magento vulnerability

New wave of extortion attacks targeting exposed MongoDB databases

The real lesson for organizations

These attacks remind us of a basic but often overlooked fact: cybersecurity starts with proper configuration. Simple authentication, limited internet exposure , and regular software updates would be enough to prevent the vast majority of these incidents.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In an era where attention is focused on sophisticated ransomware gangs, “low-cost” attacks on open MongoDB databases prove that the most dangerous adversaries are often those that exploit the most basic flaws.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS