Cyber Security News

MongoDB Cyber Attack, Customer Data Exposed

MongoDB has experienced a security incident in which unauthorized access to its corporate systems was identified.

However, the company confirmed that there was no evidence of access to any customer’s system logs. MongoDB is currently investigating the incident with authorities and forensic experts.

This incident was discovered on Saturday (16th December 2023) when there was a suspicious activity of unauthorized access to their corporate systems. It was found later that the unauthorized access had a longer period before it was detected.

Incident Response Report

According to the reports shared with Cyber Security News, the security incident involving this unauthorized access to their corporate system included customer account metadata, contact information, customer names, phone numbers, and email addresses.

However, no security vulnerability was identified in any MongoDB products as part of this incident. In addition to this, the company also confirmed that the MongoDB Atlas cluster had no evidence of unauthorized access.

MongoDB specified that MongoDB Atlas cluster authentication has a separate system from MongoDB corporate systems, and there was no evidence of compromise on the authentication system.

Login Spike

After the first incident report of this incident, there was a second incident, which stated a high number of login attempts that resulted in issues with Atlas and the MongoDB support portal.

MongoDB confirmed that this activity was unrelated to the security incident and urged their users to try again after a few minutes.

Investigations are still ongoing, and a complete incident report about this incident has yet to be published. Organizations must keep all their systems updated and patch all the products appropriately to prevent these kinds of incidents.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago