Threat reportExtortionTL-2026-0023

MongoDB Data Extortion Campaign - 1,400+ Databases Ransacked

highACTIVE

MongoDB Data Extortion Campaign (TL-2026-0023), also tracked as MongoDB Ransom, is a high-severity extortion threat scored CVSS 8.6, first published 2026-02-02. It carries a reported Russia nexus and is not formally attributed, affects MongoDB MongoDB, maps to 27 MITRE ATT&CK techniques (T1020, T1041, T1046), and is covered by 13 detection rules and 47 indicators of compromise.

CVSS
8.6/10High
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
0Not attributed
Detection rules
13SPL · KQL · Sigma
IOCs
47Indicators of compromise

Key facts for TL-2026-0023

Threat ID
TL-2026-0023
Also known as
MongoDB Ransom, Database Extortion, MongoDB Wiper
Severity
HIGH
CVSS
8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
EXTORTION
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
Information Technology, E-Commerce, Healthcare, Education, Startups, Research and Development, Financial Services
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
13
Indicators of compromise
47

Malware and tooling in MongoDB Data Extortion Campaign

Malware and tooling: Masscan, Shodan

How MongoDB Data Extortion Campaign works

Automated MongoDB data extortion campaigns have ransacked 1,400+ databases in single waves, operated by competing actor groups (Harak1r1, Kraken0, Cru3lty, Unistellar, m0ng0d4t4b4s3) who run industrialized scan→dump→wipe→ransom pipelines. The operation exploits MongoDB's historical default of binding to 0.0.0.0 with no authentication — a configuration that exposed 68,000+ instances during the 2017 'MongoDB Apocalypse' and continues exposing tens of thousands in 2024-2026. The extortion pipeline is fully automated: Shodan/Masscan enumerate port 27017 → scripts connect without auth → databases are exported (or more commonly, NOT backed up) → all collections are dropped → a single collection 'README' or 'WARNING' is inserted containing a Bitcoin address and ransom demand ($200-$1,000 BTC). The ransom economy is built on a fundamental deception: most attackers do NOT actually copy the victim's data before wiping it. They simply destroy and demand payment for data they never possessed. Analysis of Bitcoin addresses associated with extortion campaigns shows payment rates of 1-5%, generating estimated $100K-$500K per campaign wave across thousands of targets. The operation evolved through distinct phases: Phase 1 (2017 'MongoDB Apocalypse') — Harak1r1 pioneered mass automated extortion, hitting 10,000+ databases in days; Phase 2 (2018-2020) — competitor groups (Cru3lty, Unistellar) entered, overwriting each other's ransom notes; Phase 3 (2020-2022) — 'Meow' attacks emerged, wiping databases without ransom demands (pure destruction); Phase 4 (2023-2026) — evolution to multi-database targeting (MongoDB + Elasticsearch + Redis + Cassandra), increased ransom amounts, and more sophisticated victim selection (targeting databases with valuable data indicators). The 1,400+ databases hit in single campaigns demonstrate the industrial scale: one operator with a single script can extort thousands of victims in hours. The marginal cost per victim is effectively zero — scanning is free, connection requires no credentials, and Bitcoin collection is automated. This is ransomware economics without the ransomware: no encryption, no malware, no exploitation — just connecting to an open door and stealing what's inside.

The MongoDB extortion ecosystem represents the most efficient cybercrime operation per unit of effort in history. Unlike ransomware (which requires malware development, delivery mechanisms, encryption, and decryption infrastructure), MongoDB extortion requires only: (1) a Shodan API key or Masscan installation, (2) a MongoDB client (mongosh/mongo), (3) a Bitcoin wallet, and (4) a simple script.

The automated extortion pipeline:

STEP 1 — DISCOVERY: Attackers enumerate internet-facing MongoDB instances on port 27017 using Shodan, Censys, or Masscan. Shodan query: 'product:MongoDB port:27017' returns tens of thousands of results. Each result includes IP, port, version, and sometimes database names — enough to assess target value before connecting.

STEP 2 — RECONNAISSANCE: The script connects to each target without authentication (MongoDB's pre-4.0 default bound to 0.0.0.0 with no auth). The attacker runs 'show dbs' to enumerate databases, 'db.stats()' to assess size, and collection names to gauge value (databases named 'production', 'customers', 'orders', 'users' are high-value targets).

STEP 3 — EXFILTRATION (OR NOT): Here lies the fundamental deception. SOME operators export the data via mongodump before wiping (enabling actual data return on ransom payment). MOST operators skip this step entirely — the data volume is too large to store economically, and storing victim data creates legal risk. They simply proceed to deletion.

STEP 4 — DESTRUCTION: The script drops all user-created databases and collections. This takes seconds via 'db.dropDatabase()' for each database. Years of data destroyed in a single API call.

STEP 5 — RANSOM NOTE: A new database (often named 'README', 'WARNING', 'PLEASE_READ', 'RECOVER_YOUR_DATA') is created containing a single document with: a Bitcoin address, a ransom amount ($200-$1,000 in BTC), an email address for 'negotiation', and a deadline (typically 48 hours). Example note: 'All your data is backed up. You must pay 0.015 BTC to [address] to recover it. Email: [address]. Deadline: 48 hours or data is deleted permanently.'

STEP 6 — COLLECTION: Victims who pay receive nothing (data was never backed up) or receive a partial dump. Bitcoin addresses are monitored for payments. Multiple campaigns use the same addresses, enabling tracking of total revenue.

Actor group profiles:

- HARAK1R1: Pioneer of mass MongoDB extortion (December 2016 - January 2017). First to automate the scan→wipe→ransom pipeline at scale. Hit 10,000+ databases in the initial 'MongoDB Apocalypse'. Demanded 0.2 BTC (~$200 at 2017 prices). Set the template all subsequent actors follow. Bitcoin analysis showed ~$28,000 received from initial campaign.

- KRAKEN0: Active 2017-2019. Targeted both MongoDB and Elasticsearch instances. Known for overwriting competitor ransom notes — would wipe databases already ransomed by Harak1r1 and replace with their own note. Demonstrated the 'overwrite' problem: multiple actors competing for the same victims means data is destroyed multiple times.

- CRU3LTY: Active 2018-2020. Focused on smaller databases with indicators of development/startup environments. Demanded lower ransoms ($150-$300) but at higher volume. Operational pattern: scan during weekends when admin response is slowest.

- UNISTELLAR: Active 2019-2021. Larger-scale operations hitting 12,000+ MongoDB instances in single campaigns. Used automated scripts that connected to Shodan API in real-time, maintaining persistent scanning. More sophisticated victim selection: filtered for databases > 100MB (indicating real data vs test instances).

- M0NG0D4T4B4S3: Active 2022-2026. Latest generation extending attacks to Elasticsearch, Redis, Cassandra, and CouchDB. Multi-database scanning pipeline. Higher ransom demands ($500-$1,000) reflecting cryptocurrency price changes. Uses Tor-based email for communication. Represents the evolution from MongoDB-specific to general exposed-database extortion.

- MEOW ATTACKS (2020-2022): Distinctive variant — databases wiped with 'meow' suffix but NO ransom note left. Pure data destruction without financial motive. Speculation: security vigilantes, competitors eliminating already-ransomed instances, or actors testing destructive capabilities. Hit 4,000+ MongoDB and Elasticsearch instances.

Ransom economics analysis: - Average demand: $200-$1,000 BTC per database - Payment rate: 1-5% of victims (estimated from Bitcoin address analysis) - Revenue per campaign (1,400 targets): $2,800-$70,000 at 1-5% payment rate - Cost per campaign: Near-zero (Shodan subscription $59/month, MongoDB client free, script development hours) - ROI: 50x-1,000x+ return on investment - Victim reality: 90%+ of paying victims never receive their data back - Total ecosystem revenue (2017-2026): Estimated $5M-$20M across all actor groups

The ransom note deception: Security researchers (including Bob Diachenko, Victor Gevers, and the GDI Foundation) analyzed hundreds of extortion cases and found that the majority of attackers NEVER export victim data. The ransom notes claim 'your data is backed up on our servers' — this is almost always false. Victims who pay are paying for nothing. The operation is extortion based on fear, not actual data possession.

MongoDB's response timeline: - Pre-2016: MongoDB default config bound to 0.0.0.0 with no authentication. Any internet connection = full admin access. - MongoDB 2.6 (2014): Added --auth flag but not enabled by default. - MongoDB 3.6 (2017): Changed default binding to localhost (127.0.0.1) — the most impactful single security change. NEW installations are safe. - MongoDB 4.0 (2018): Authentication enabled by default in some deployment modes. - MongoDB 7.0+ (2023): Enhanced security defaults, SCRAM authentication, TLS by default in Atlas. - Problem: Legacy instances from pre-3.6 era still running with 0.0.0.0 binding. Cloud deployments with misconfigured security groups. Docker deployments exposing port 27017. Every new wave of extortion targets the SAME long-standing misconfiguration — the fix exists but isn't applied.

Why this continues (2024-2026): 1. Legacy instances: Pre-3.6 MongoDB installations still running in production 2. Docker misconfigurations: docker run -p 27017:27017 mongo exposes to 0.0.0.0 3. Cloud security groups: AWS/GCP/Azure VMs with 0.0.0.0/0 on port 27017 4. Development instances promoted to production without hardening 5. Backup negligence: No backups = total data loss when wiped, increasing ransom payment pressure

MITRE ATT&CK techniques used in TL-2026-0023

exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts

collection

T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories

persistence

T1098 Account Manipulation; T1133 External Remote Services; T1136 Create Account

initial-access

T1190 Exploit Public-Facing Application

credential-access

T1212 Exploitation for Credential Access

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in MongoDB Data Extortion Campaign

  • MongoDB — MongoDB
    Vulnerable versions: All versions exposed without authentication

Remediation for MongoDB Data Extortion Campaign

Immediate actions

  • Enable MongoDB authentication immediately
  • Bind MongoDB to localhost or internal IPs only
  • Block port 27017 from external access at firewall
  • Check for ransom notes in existing databases
  • Restore from backup if compromised (do NOT pay ransom)

Workarounds

  • Use SSH tunneling for remote MongoDB access
  • Deploy MongoDB behind VPN
  • Use firewall rules to restrict source IPs

Longer-term hardening

  • Implement MongoDB access controls and RBAC
  • Enable TLS encryption for MongoDB connections
  • Regular backup verification and testing
  • Network segmentation for database tier
  • Continuous scanning for exposed databases

Weaknesses (CWE) in MongoDB Data Extortion Campaign

CWE-306, CWE-284

Timeline of MongoDB Data Extortion Campaign

  • MongoDB 2.6 introduces --auth flag for authentication support. However, authentication is NOT enabled by default. Default configuration binds to 0.0.0.0 (all interfaces) with no authentication. Any internet connection provides full admin access. The insecure default persists.
  • Harak1r1 begins automated MongoDB extortion campaign — the first of its kind at scale. Script scans Shodan for port 27017, connects without auth, drops databases, inserts ransom note demanding 0.2 BTC. Victor Gevers and GDI Foundation begin tracking and notifying victims. Source: GDI Foundation, BleepingComputer
  • MongoDB Apocalypse: 10,000+ databases ransomed in days. Multiple actor groups (Harak1r1, Kraken0, Cru3lty) compete for targets. Competitors overwrite each other's ransom notes, destroying data multiple times. BleepingComputer reports 'MongoDB apocalypse is here.' 68,000+ exposed instances on Shodan. Source: BleepingComputer, KrebsOnSecurity
  • Extortion expands beyond MongoDB: Elasticsearch, CouchDB, Hadoop, and Redis instances targeted with identical pipeline. 35,000+ Elasticsearch instances exposed. Actor groups adapt scripts for multiple database platforms. The scan→wipe→ransom pipeline becomes database-agnostic.
  • MongoDB 3.6 released with default binding changed to localhost (127.0.0.1). This is the single most impactful security change — NEW installations are no longer internet-accessible by default. However, existing pre-3.6 installations remain exposed. Docker deployments continue using 0.0.0.0 binding. Source: MongoDB release notes
  • Unistellar actor group launches massive MongoDB extortion wave hitting 12,000+ instances in a single campaign. Demonstrates evolution: automated Shodan API integration, target filtering by database size (>100MB), higher ransom demands reflecting BTC price increase. Most sophisticated campaign to date.
  • Meow attacks begin: MongoDB and Elasticsearch databases wiped with 'meow' suffix but NO ransom note. 4,000+ databases destroyed. Speculation ranges from security vigilantes to competitors eliminating already-ransomed instances. Pure data destruction without financial motive. Source: BleepingComputer, Bob Diachenko
  • Extortion campaigns evolve to multi-database targeting. m0ng0d4t4b4s3 actor operates scripts scanning MongoDB, Elasticsearch, Redis, Cassandra, and CouchDB simultaneously. Single pipeline targets all exposed databases regardless of technology. Higher ransom demands ($500-$1,000).
  • Elasticsearch 8.0 enables security by default, paralleling MongoDB 3.6's fix. New Elasticsearch installations require authentication. Combined with MongoDB's fix, this reduces the exposed database surface — but legacy instances and misconfigured cloud deployments remain vulnerable.
  • Single extortion campaign hits 1,400+ MongoDB databases in one wave. Automated pipeline completes scan→wipe→ransom for each target in under 5 seconds. Actor demands $500 BTC per database. Bitcoin address analysis shows 1-5% payment rate. Most victims who pay never receive data — it was never backed up.
  • Despite 8+ years of public warnings, tens of thousands of MongoDB instances remain exposed on Shodan. Legacy installations, Docker misconfigurations, and cloud security group errors continue creating new victims. The extortion pipeline costs near-zero to operate, making it perpetually profitable.
  • MongoDB extortion directly parallels emerging AI infrastructure extortion: Ollama (175K exposed, compute theft), exposed Redis (cryptomining), and exposed Elasticsearch (data theft). The pattern is identical: popular database/service + no auth by default + internet exposure = automated exploitation. MongoDB pioneered the pattern; AI infrastructure repeats it at worse economics.
  • Current state: MongoDB extortion continues as a persistent low-sophistication, high-volume cybercrime operation. Actor groups evolved from MongoDB-specific to multi-database. Ransom demands increased from $200 to $1,000. Payment rates remain 1-5%. The fundamental problem unchanged: exposed databases without authentication = automated extortion at zero marginal cost.
  • As of 2026-05-29, this MongoDB data-extortion campaign is still active: Flare and a May-2026 corpus study report exposed MongoDB instances showing a 99.8% ransom-note compromise rate (3,525/3,532), ~1,400 hit per wave, and one automated campaign running Oct-2023 through May-2026. It is a config/misconfiguration threat (CWE-306/284, no CVE, so no KEV/patch applies); the pure-destruction "Meow" variant died off but the low-ransom extortion economy keeps growing.

Sources cited for MongoDB Data Extortion Campaign

Detection coverage for TL-2026-0023

As of 2026-02-02, Threadlinqs Intelligence publishes 13 detection rule(s) for TL-2026-0023 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

13 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
47 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats