Feeds.Feedburner Mass Database Extortion Campaign Targets Over 30,000 Systems
Article Content
- •Over 30,000 databases targeted in ransom attacks over five years.
- •46.3% of affected databases contained ransom or wipe notes.
- •Attackers shifted focus from data destruction to extortion for profit.
A five-year study revealed that 30,515 exposed databases were targeted by ransom attacks, leading to significant damage even without payments. The Ransomnews Research Team's analysis from May 2021 to May 2026 found that 46.3% of these databases contained ransom or wipe notes, affecting over 215 billion records. Despite the low payment rate, attackers utilized 514 unique bitcoin wallets, with 318 showing no transaction history. The study highlighted a shift from destructive attacks to extortion, emphasizing the need for enhanced security measures. Compromised systems included MongoDB and MySQL, which were almost universally affected when exposed. The total confirmed revenue from these attacks was approximately $753,000, indicating a lucrative but damaging trend in the ransomware economy.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…