MongoDB instances are suffering from data extortion attacks, so make sure you’re protected



  • Over 200,000 MongoDB servers misconfigured, 3,000 exposed without passwords
  • Hackers wiped databases and left ransom notes demanding payments in bitcoins
  • Many servers are running outdated versions, vulnerable to DoS and persistent access

If you are running a MongoDB instance, you may want to double-check your configuration, as experts have noted that hackers are looking to extort money from you.

Flare security researchers reported finding more than 200,000 misconfigured MongoDB servers whose data is available to anyone who knows where to look. About half of them expose operational information and about 3,000 can be accessed without a password.



Leave a Comment

Your email address will not be published. Required fields are marked *