MongoDB instances are falling victim to data extortion attacks, so make sure you’re protected


  • Over 200,000 MongoDB servers misconfigured, 3,000 exposed without password
  • Hackers wiped databases and left ransom notes demanding bitcoin payments
  • Many servers are running outdated versions, vulnerable to DoS and persistent access

If you’re running a MongoDB instance, you may want to double-check your configuration, as experts have reported hackers looking to extort money from you.

Security researchers Flare reported discovering more than 200,000 misconfigured MongoDB servers whose data is accessible to anyone who knows where to look. About half of them expose operational information, and about 3,000 are accessible without a password.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top