Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Over 1,400 MongoDB Databases Ransacked by Threat Actor

Posted on February 2, 2026February 2, 2026 By CWS

Unprotected MongoDB situations stay a straightforward goal for financially motivated hackers, with over 1,400 servers presently displaying indicators of compromise, menace administration agency Flare reviews.

Ransacking MongoDB databases was a pattern roughly a decade in the past, with over 33,000 situations hijacked in an enormous marketing campaign detailed in early 2017.

As a result of database house owners did not correctly defend internet-accessible MongoDB situations, hackers accessed them, wiped their content material, and dropped ransom notes demanding cost in trade for the erased content material.

Now, Flare says that there are over 200,000 MongoDB servers publicly discoverable, with greater than 100,000 disclosing operational data.

Alarmingly, 3,100 databases are uncovered to the web with out correct restrictions, permitting anybody to entry them.

Of those, 1,416 situations (45.6%) have been compromised, with their contents changed with ransom notes usually demanding a $500 ransom cost in Bitcoin, Flare says.Commercial. Scroll to proceed studying.

In 98% of those circumstances, the ransom notes point out the identical bitcoin tackle, strongly suggesting that the MongoDB ransacking was carried out by the identical menace actor.

The remaining 1,684 servers (54.4%) don’t present indicators of an infection, and Flare believes that not less than a few of their house owners may need paid a ransom,

“This means that the menace actor’s earnings from this marketing campaign may vary from $0 USD (assuming all remaining servers have been check environments that have been merely taken offline) to as a lot as $842,000,” Flare notes.

In the intervening time, the menace actor’s Bitcoin pockets seems to have obtained solely round $400, suggesting that the ransacking exercise may not have been as worthwhile for the hacker.

Flare’s investigation additionally revealed that over 95,000 of the recognized servers (46.3%) had not less than one vulnerability. A lot of the flaws may result in denial-of-service (DoS) situations.

“In our case, the one actually problematic belongings are the roughly 3,100 MongoDB situations that have been uncovered with out correct entry controls,” Flare notes.

Associated: Cyber Fraud Overtakes Ransomware as Prime CEO Concern: WEF

Associated: In Different Information: 8,000 Ransomware Assaults, China Hacked US Gov Emails, IDHS Breach Impacts 700k

Associated: Ransomware Funds Surpassed $4.5 Billion: US Treasury

Associated: Ransomware Funds Dropped in Q3 2025: Evaluation

Security Week News Tags:Actor, Databases, MongoDB, Ransacked, Threat

Post navigation

Previous Post: Japan, Britain to Boost Cybersecurity and Critical Minerals Cooperation as China’s Influence Grows
Next Post: Securing the Mid-Market Across the Complete Threat Lifecycle

Related Posts

Alleged Chinese State Hacker Wanted by US Arrested in Italy Security Week News
Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack Security Week News
Former US Soldier Who Hacked AT&T and Verizon Pleads Guilty Security Week News
Rethinking Security for Agentic AI Security Week News
Vulnerabilities Expose Helmholz Industrial Routers to Hacking Security Week News
In Other News: Docker AI Attack, Google Sues Chinese Cybercriminals, Coupang Hacked by Employee Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Pulsar RAT Attacking Windows Systems via Per-user Run Registry Key and Exfiltrates Sensitive Details
  • Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
  • Hackers Exploiting Microsoft Office 0-day Vulnerability to Deploy Malware
  • Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities
  • Autonomous AI Agents Are Becoming the New Operating System of Cybercrime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Pulsar RAT Attacking Windows Systems via Per-user Run Registry Key and Exfiltrates Sensitive Details
  • Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
  • Hackers Exploiting Microsoft Office 0-day Vulnerability to Deploy Malware
  • Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities
  • Autonomous AI Agents Are Becoming the New Operating System of Cybercrime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark