Multiple organizations with exposed MongoDB databases
January 30, 2026
•[ MongoDB, data breach, ransomware ]
A threat actor actively accessed, queried, and ransacked more than 1400 publicly exposed MongoDB application servers, exfiltrating data and leaving ransom notes demanding payment in exchange for deletion or non-disclosure of the stolen information.
MongoDB
December 13, 2023
•[ leak, technology ]
MongoDB warns that its corporate systems were breached and that customer data was exposed in a cyberattack that was detected by the company earlier this week.
Verifications.io
February 25, 2019
•[ leak, misconfiguration, technology ]
In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable.
MongoDB
January 1, 2019
poor security
MongoDB
January 1, 2019
•[ technology ]
poor security
Princeton University
January 7, 2017
•[ hack, misconfiguration, education ]
Princeton University is one of the 27,000 victims that have their data wiped by attackers leveraging a vulnerable MongoDB.
Coinroll Bitcoin Casino
April 17, 2016
•[ financial, misconfiguration, finance ]
Coinroll Bitcoin Casino admits that several users had the funds on their online accounts stolen. The breach could be related to an open MongoDB.