MongoDB and Elasticsearch: New Research Reveals 62% of Database Ransom Wallets Were Never Paid

MongoDB and Elasticsearch: New Research Reveals 62% of Database Ransom Wallets Were Never Paid

Industrial-Scale Database Extortion: A Five-Year Census Reveals Massive Damage with Minimal Payoff

A five-year investigation by the Ransomnews Research Team uncovered a staggering scale of exposed databases on the public internet 65,907 instances with 46.3% (30,515) already compromised by ransom or wipe attacks. The study, conducted between May 2021 and May 2026, traced 514 distinct Bitcoin wallets linked to these attacks, revealing a stark imbalance: 62% of wallets received no payments, yet the damage an estimated 215 billion records destroyed or exfiltrated was already done.

Key Findings

  • Exposure = Compromise: Nearly 100% of exposed MongoDB, MySQL, Elasticsearch, and Kibana instances carried ransom notes when observed, proving that unsecured databases are almost immediately targeted.
  • Automated, Low-Effort Attacks: A single Bitcoin wallet appeared in 1,283 ransom notes across 49 countries, demanding 0.01 BTC (~$760) a clear sign of scripted, volume-driven extortion.
  • Concentrated Profits: Of the 9.78 BTC (~$753,000) paid across five years, the top 10 wallets captured 43%, while the top 50 took 82.8%. Most operators earn little, but a few dominate the profitable end.
  • Shift from Destruction to Extortion: Early "wiper" attacks (like the 2020 Meow campaign) have nearly vanished, replaced by ransom notes even if most victims don’t pay.

How the Attacks Work

  • Industrial-Scale Scripts: Attackers scan for open database ports, drop templated ransom notes (e.g., read_me_to_recover, btc_ransom_note), and move on. Payment is optional; the damage is not.
  • Disposable Infrastructure: High-volume contact emails (e.g., dar0kmdb@tutanota.com) pair with the same wallets across thousands of attacks, suggesting a small group of operators reusing tools.
  • Global Distribution: The most affected countries China (11,874), U.S. (4,194), Germany (2,026) reflect cloud-hosting density rather than targeted negligence.

The Bigger Picture

Database extortion remains an overlooked corner of ransomware, lacking the branding of high-profile groups. Yet, its impact is severe: exposed databases are compromised within hours, and even when ransoms go unpaid, the data loss is irreversible. The economics are brutal $25 per ransom-marked database but the operational harm is vast. The lesson for defenders is clear: unsecured databases are not at risk they are already compromised.

Source: https://www.linkedin.com/pulse/new-research-reveals-62-database-ransom-wallets-8ynre

MongoDB cybersecurity rating report: https://www.rankiteo.com/company/mongodbinc

Elasticsearch Expert cybersecurity rating report: https://www.rankiteo.com/company/elasticsearch-experts

"id": "MONELA1783283101",
"linkid": "mongodbinc, elasticsearch-experts",
"type": "Ransomware",
"date": "5/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Cloud hosting',
                                     'Technology',
                                     'Data services'],
                        'location': ['China',
                                     'U.S.',
                                     'Germany',
                                     '49 countries total'],
                        'type': 'Database owners (various industries)'}],
 'attack_vector': 'Exposed databases (MongoDB, MySQL, Elasticsearch, Kibana) '
                  'with open ports',
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': True,
                 'file_types_exposed': ['Database files (MongoDB, MySQL, '
                                        'Elasticsearch, Kibana)'],
                 'number_of_records_exposed': '215 billion',
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (varies by database)',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information',
                                              'General database records']},
 'date_detected': '2021-05',
 'date_publicly_disclosed': '2026-05',
 'description': 'A five-year investigation by the Ransomnews Research Team '
                'uncovered 65,907 exposed databases on the public internet, '
                'with 46.3% (30,515) already compromised by ransom or wipe '
                'attacks. The study revealed that 62% of 514 distinct Bitcoin '
                'wallets received no payments, yet an estimated 215 billion '
                'records were destroyed or exfiltrated. Nearly 100% of exposed '
                'MongoDB, MySQL, Elasticsearch, and Kibana instances carried '
                'ransom notes, indicating immediate targeting of unsecured '
                'databases. Attacks are automated, low-effort, and '
                'volume-driven, with a single Bitcoin wallet appearing in '
                '1,283 ransom notes across 49 countries. The top 10 wallets '
                'captured 43% of the 9.78 BTC (~$753,000) paid over five '
                "years, while early 'wiper' attacks have been replaced by "
                'ransom notes.',
 'impact': {'data_compromised': '215 billion records destroyed or exfiltrated',
            'financial_loss': '~$753,000 (9.78 BTC) paid in ransoms over five '
                              'years',
            'operational_impact': 'Irreversible data loss, compromised '
                                  'databases',
            'systems_affected': '65,907 exposed databases, 30,515 compromised'},
 'initial_access_broker': {'entry_point': 'Exposed database ports'},
 'investigation_status': 'Completed (five-year study)',
 'lessons_learned': 'Unsecured databases are almost immediately targeted and '
                    'compromised. Automated, volume-driven attacks dominate, '
                    'with minimal financial payoff for most operators but '
                    'severe data loss for victims. Defenders must prioritize '
                    'securing exposed databases to prevent irreversible '
                    'damage.',
 'motivation': 'Financial gain (ransom payments), data '
               'destruction/exfiltration',
 'post_incident_analysis': {'corrective_actions': 'Close open database ports, '
                                                  'implement network '
                                                  'segmentation, enhance '
                                                  'monitoring, and assume '
                                                  'compromise for exposed '
                                                  'databases',
                            'root_causes': 'Unsecured databases exposed to the '
                                           'public internet, lack of proactive '
                                           'security measures'},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransom_demanded': '0.01 BTC (~$760) per database',
                'ransom_paid': '9.78 BTC (~$753,000) over five years'},
 'recommendations': ['Secure exposed databases by closing open ports',
                     'Implement network segmentation and enhanced monitoring',
                     'Assume exposed databases are already compromised and act '
                     'accordingly',
                     'Adopt proactive database security measures to prevent '
                     'targeting'],
 'references': [{'date_accessed': '2026-05',
                 'source': 'Ransomnews Research Team'}],
 'threat_actor': 'Automated script operators (small group reusing tools)',
 'title': 'Industrial-Scale Database Extortion: A Five-Year Census Reveals '
          'Massive Damage with Minimal Payoff',
 'type': 'Ransomware/Extortion',
 'vulnerability_exploited': 'Unsecured databases exposed to the public '
                            'internet'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.