MongoDB instances are hit in data extortion attacks, so make sure you’re protected


  • Over 200,000 MongoDB servers misconfigured, 3,000 exposed without passwords
  • Hackers deleted databases, left ransom notes and demanded bitcoin payments
  • Many servers run outdated versions, vulnerable to DoS and persistent access

If you’re running a MongoDB instance, you might want to double-check your configuration, as experts have flagged that hackers are looking to extort money from you.

Security researchers Flare have reported finding more than 200,000 misconfigured MongoDB servers whose data is available to anyone who knows where to look. About half of them reveal operational information, and approximately 3,000 can be accessed without a password.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top