Threat actors are conducting a highly automated extortion campaign against publicly exposed MongoDB instances, exploiting missing/weak authentication and, in some cases, outdated vulnerable versions to gain access, wipe databases, and replace contents with ransom notes demanding cryptocurrency. Reporting indicates the activity is largely opportunistic and driven by internet-wide discovery (e.g., Shodan-style scanning), with little evidence of targeted intrusion or post-exploitation beyond data destruction and claimed exfiltration; victims are typically asked to pay to recover data, despite no reliable evidence that data is restored after payment.
Findings cited from Flare’s research indicate the scale of exposure is significant: more than 200,000 MongoDB servers were publicly discoverable, with about 3,100 described as fully exposed without access restrictions; of those, 1,416 (45.6%) were already compromised and wiped, with ransom demands commonly around $500 in Bitcoin. Wallet reuse strongly suggests centralization of the activity: only a handful of wallets were observed, with bc1qe2l4ffmsqfdu43d7n76hp2ksmhclt5g9krx3du appearing in over 98% of cases, consistent with a single dominant actor or closely coordinated group; the primary risk driver is misconfiguration rather than high-impact RCE, as many observed vulnerabilities were assessed as more likely to enable denial-of-service than full compromise on their own.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting cited in the references said attackers were also exploiting MongoBleed (CVE-2025-14847) against affected MongoDB version ranges in real-world attacks, alongside attention to CVE-2024-3372. The coverage emphasized that vulnerability exploitation was secondary to the larger problem of exposed and unauthenticated deployments.
Analysis found the same Bitcoin wallet in the vast majority of incidents, including one report that said a single wallet appeared in 98% of observed cases. This wallet reuse suggested that one dominant threat actor or a closely coordinated group was responsible for most of the extortion activity.
Flare reported that among 3,100 fully exposed MongoDB servers without access restrictions, 1,416 had already been compromised and wiped, a 45.6% compromise rate. The firm also noted that while more than 200,000 MongoDB servers were publicly discoverable, misconfiguration and missing access controls were the primary drivers of the attacks.
Attackers began systematically scanning for internet-exposed MongoDB instances with missing authentication, accessing them without credentials, and wiping or overwriting databases before leaving Bitcoin ransom notes. The activity was characterized as opportunistic and highly automated, with no credible evidence that payment restores data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.