Mass Database Extortion Campaign Targets Over 30,000 Systems

Mass Database Extortion Campaign Targets Over 30,000 Systems

First seen 27 May 2026, 17:09 UTC Securityaffairs.CoFeeds.Feedburner 79% similarity 64.5

Article Content

Browse articles
ThreatCluster

A five-year study revealed that 30,515 exposed databases were targeted by ransom attacks, leading to significant damage even without payments. The Ransomnews Research Team's analysis from May 2021 to May 2026 found that 46.3% of these databases contained ransom or wipe notes, affecting over 215 billion records. Despite the low payment rate, attackers utilized 514 unique bitcoin wallets, with 318 showing no transaction history. The study highlighted a shift from destructive attacks to extortion, emphasizing the need for enhanced security measures. Compromised systems included MongoDB and MySQL, which were almost universally affected when exposed. The total confirmed revenue from these attacks was approximately $753,000, indicating a lucrative but damaging trend in the ransomware economy.

Key Points: • Over 30,000 databases targeted in ransom attacks over five years. • 46.3% of affected databases contained ransom or wipe notes. • Attackers shifted focus from data destruction to extortion for profit.

ThreatCluster AI

Timeline

2021-05-01
Study on ransomware economy begins
The Ransomnews Research Team starts a five-year analysis of exposed databases and ransom attacks.
Security Affairs
2026-05-26
Study findings published
The Ransomnews Research Team reports on the impact of ransom attacks on over 30,000 databases.
Securityaffairs.Co
2026-05-27
Current damage assessment released
The study reveals significant damage from ransom attacks despite low payment rates, affecting over 215 billion records.
Feeds.Feedburner

Community

Browse all →

Tracked Entities in This Story