MongoDB Data Extortion Attacks Continue with Low Ransom Demands
Summary
Hide ▲
Show ▼
A threat actor is targeting exposed MongoDB instances in automated data extortion attacks, demanding low ransoms of approximately $500 in Bitcoin to restore deleted data. The attacker exploits misconfigured databases that allow unrestricted access, with around 1,400 servers compromised. Researchers from Flare discovered over 208,500 exposed MongoDB servers, of which 3,100 could be accessed without authentication. Nearly half of these accessible databases were already compromised, with ransom notes left behind. The attacks are smaller in scale compared to previous waves but continue to target vulnerable instances. The threat actor uses a limited number of Bitcoin wallet addresses, with one address prevalent in about 98% of the cases, suggesting a single actor behind these attacks. Additionally, nearly half of the exposed MongoDB servers run older versions vulnerable to n-day flaws, though most of these flaws only allow denial-of-service attacks. Flare recommends securing MongoDB instances by avoiding public exposure, using strong authentication, enforcing firewall rules, updating to the latest version, and continuously monitoring for unauthorized activity.
Timeline
-
01.02.2026 18:27 1 articles · 23h ago
MongoDB Data Extortion Attacks Continue with Low Ransom Demands
A threat actor is targeting exposed MongoDB instances in automated data extortion attacks, demanding low ransoms of approximately $500 in Bitcoin to restore deleted data. The attacker exploits misconfigured databases that allow unrestricted access, with around 1,400 servers compromised. Researchers from Flare discovered over 208,500 exposed MongoDB servers, of which 3,100 could be accessed without authentication. Nearly half of these accessible databases were already compromised, with ransom notes left behind. The attacks are smaller in scale compared to previous waves but continue to target vulnerable instances. The threat actor uses a limited number of Bitcoin wallet addresses, with one address prevalent in about 98% of the cases, suggesting a single actor behind these attacks. Additionally, nearly half of the exposed MongoDB servers run older versions vulnerable to n-day flaws, though most of these flaws only allow denial-of-service attacks.
Show sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
Information Snippets
-
The threat actor targets exposed MongoDB instances with low ransom demands of approximately $500 in Bitcoin.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
-
Around 1,400 MongoDB servers have been compromised in these attacks.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
-
Researchers discovered over 208,500 exposed MongoDB servers, with 3,100 accessible without authentication.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
-
Nearly half (45.6%) of the accessible MongoDB databases were already compromised, with ransom notes left behind.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
-
The ransom notes demanded a payment of 0.005 BTC within 48 hours, with one Bitcoin wallet address used in 98% of the cases.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27
-
Nearly half (95,000) of the exposed MongoDB servers run older versions vulnerable to n-day flaws, though most allow only denial-of-service attacks.
First reported: 01.02.2026 18:271 source, 1 articleShow sources
- Exposed MongoDB instances still targeted in data extortion attacks — www.bleepingcomputer.com — 01.02.2026 18:27