Industrial-Scale Database Extortion: A Five-Year Census Reveals Massive Damage with Minimal Payoff
A five-year investigation by the Ransomnews Research Team uncovered a staggering scale of exposed databases on the public internet 65,907 instances with 46.3% (30,515) already compromised by ransom or wipe attacks. The study, conducted between May 2021 and May 2026, traced 514 distinct Bitcoin wallets linked to these attacks, revealing a stark imbalance: 62% of wallets received no payments, yet the damage an estimated 215 billion records destroyed or exfiltrated was already done.
Key Findings
- Exposure = Compromise: Nearly 100% of exposed MongoDB, MySQL, Elasticsearch, and Kibana instances carried ransom notes when observed, proving that unsecured databases are almost immediately targeted.
- Automated, Low-Effort Attacks: A single Bitcoin wallet appeared in 1,283 ransom notes across 49 countries, demanding 0.01 BTC (~$760) a clear sign of scripted, volume-driven extortion.
- Concentrated Profits: Of the 9.78 BTC (~$753,000) paid across five years, the top 10 wallets captured 43%, while the top 50 took 82.8%. Most operators earn little, but a few dominate the profitable end.
- Shift from Destruction to Extortion: Early "wiper" attacks (like the 2020 Meow campaign) have nearly vanished, replaced by ransom notes even if most victims don’t pay.
How the Attacks Work
- Industrial-Scale Scripts: Attackers scan for open database ports, drop templated ransom notes (e.g., read_me_to_recover, btc_ransom_note), and move on. Payment is optional; the damage is not.
- Disposable Infrastructure: High-volume contact emails (e.g., dar0kmdb@tutanota.com) pair with the same wallets across thousands of attacks, suggesting a small group of operators reusing tools.
- Global Distribution: The most affected countries China (11,874), U.S. (4,194), Germany (2,026) reflect cloud-hosting density rather than targeted negligence.
The Bigger Picture
Database extortion remains an overlooked corner of ransomware, lacking the branding of high-profile groups. Yet, its impact is severe: exposed databases are compromised within hours, and even when ransoms go unpaid, the data loss is irreversible. The economics are brutal $25 per ransom-marked database but the operational harm is vast. The lesson for defenders is clear: unsecured databases are not at risk they are already compromised.
Source: https://www.linkedin.com/pulse/new-research-reveals-62-database-ransom-wallets-8ynre
MongoDB cybersecurity rating report: https://www.rankiteo.com/company/mongodbinc
Elasticsearch Expert cybersecurity rating report: https://www.rankiteo.com/company/elasticsearch-experts
"id": "MONELA1783283101",
"linkid": "mongodbinc, elasticsearch-experts",
"type": "Ransomware",
"date": "5/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Cloud hosting',
'Technology',
'Data services'],
'location': ['China',
'U.S.',
'Germany',
'49 countries total'],
'type': 'Database owners (various industries)'}],
'attack_vector': 'Exposed databases (MongoDB, MySQL, Elasticsearch, Kibana) '
'with open ports',
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'file_types_exposed': ['Database files (MongoDB, MySQL, '
'Elasticsearch, Kibana)'],
'number_of_records_exposed': '215 billion',
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (varies by database)',
'type_of_data_compromised': ['Personally identifiable '
'information',
'General database records']},
'date_detected': '2021-05',
'date_publicly_disclosed': '2026-05',
'description': 'A five-year investigation by the Ransomnews Research Team '
'uncovered 65,907 exposed databases on the public internet, '
'with 46.3% (30,515) already compromised by ransom or wipe '
'attacks. The study revealed that 62% of 514 distinct Bitcoin '
'wallets received no payments, yet an estimated 215 billion '
'records were destroyed or exfiltrated. Nearly 100% of exposed '
'MongoDB, MySQL, Elasticsearch, and Kibana instances carried '
'ransom notes, indicating immediate targeting of unsecured '
'databases. Attacks are automated, low-effort, and '
'volume-driven, with a single Bitcoin wallet appearing in '
'1,283 ransom notes across 49 countries. The top 10 wallets '
'captured 43% of the 9.78 BTC (~$753,000) paid over five '
"years, while early 'wiper' attacks have been replaced by "
'ransom notes.',
'impact': {'data_compromised': '215 billion records destroyed or exfiltrated',
'financial_loss': '~$753,000 (9.78 BTC) paid in ransoms over five '
'years',
'operational_impact': 'Irreversible data loss, compromised '
'databases',
'systems_affected': '65,907 exposed databases, 30,515 compromised'},
'initial_access_broker': {'entry_point': 'Exposed database ports'},
'investigation_status': 'Completed (five-year study)',
'lessons_learned': 'Unsecured databases are almost immediately targeted and '
'compromised. Automated, volume-driven attacks dominate, '
'with minimal financial payoff for most operators but '
'severe data loss for victims. Defenders must prioritize '
'securing exposed databases to prevent irreversible '
'damage.',
'motivation': 'Financial gain (ransom payments), data '
'destruction/exfiltration',
'post_incident_analysis': {'corrective_actions': 'Close open database ports, '
'implement network '
'segmentation, enhance '
'monitoring, and assume '
'compromise for exposed '
'databases',
'root_causes': 'Unsecured databases exposed to the '
'public internet, lack of proactive '
'security measures'},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_demanded': '0.01 BTC (~$760) per database',
'ransom_paid': '9.78 BTC (~$753,000) over five years'},
'recommendations': ['Secure exposed databases by closing open ports',
'Implement network segmentation and enhanced monitoring',
'Assume exposed databases are already compromised and act '
'accordingly',
'Adopt proactive database security measures to prevent '
'targeting'],
'references': [{'date_accessed': '2026-05',
'source': 'Ransomnews Research Team'}],
'threat_actor': 'Automated script operators (small group reusing tools)',
'title': 'Industrial-Scale Database Extortion: A Five-Year Census Reveals '
'Massive Damage with Minimal Payoff',
'type': 'Ransomware/Extortion',
'vulnerability_exploited': 'Unsecured databases exposed to the public '
'internet'}