Opportunistic, malware-less ransomware campaigns are targeting Internet-exposed database servers, including MySQL, Amazon Aurora MySQL, MariaDB, MongoDB, and PostgreSQL. Attackers exploit weak, default, or absent authentication to log in remotely, potentially exfiltrate records, delete or destroy the databases with legitimate administrative commands, and leave payment demands in newly created tables or collections rather than deploying file-encrypting malware.
MongoDB was the most frequently targeted platform in analyzed cloud incidents, followed by PostgreSQL, while reports also identify damaging attacks against MySQL servers. The operations may pair data destruction with double-extortion threats and can provide access for remote code execution or lateral movement. Organizations should remove public database exposure, enforce strong credentials and MFA-protected administration, maintain tested isolated backups, continuously identify exposed assets, and hunt databases for ransom-note artifacts.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Rapid7 researchers observed thousands of Internet-exposed databases being hijacked in bulk through automated attacks.
Threat actors conduct automated malware-less ransomware campaigns against Internet-facing database services with absent, default, or weak credentials. After authenticating through legitimate database protocols, they may destroy data, leave ransom-note tables or collections, and threaten to disclose allegedly exfiltrated data.
A Guardicore Labs (now Akamai) report described a campaign targeting MySQL servers in which attackers uploaded victim database dumps to a dark-web auction site to pressure victims into paying.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.