MongoDB Ransom Attacks Hit 27000 Systems

Updated Jun 2026 · Tested on Linux, Unix

MongoDB Ransom Attacks has hit 27,000 Systems in few hours from 12000 impacted servers .

Most of the mongoDB installations are exposed to exploites due to poor default access controls for super users .

Hackers are accessing MongoDB databaases and then copy and delete data from database running in default, unsecure configuration. In return of data administrators are being asked to pay ransom money by bitcoins.

What Can mongoDB DBA’s Do ?

  1. Follow Frank Harding’s Quick Steps to Secure mongoDB