3 ms·
I know a company that got hit by this. Through some mistake in configuration, they exposed their mongodb. What I understand is that the ransom request is a tota
by kahnpro 10y ago
I know a company that got hit by this. Through some mistake in configuration, they exposed their mongodb. What I understand is that the ransom request is a total scam, they didn't download or encrypt any data, just ran the drop command and inserted the ransom message.
But they didn't hit the oplog/journal, fortunately the full history (a few months of data) was still in the journal, so they were able to replay it (minus the drop commands) and restored their data.
Certainly scared a lot of people and (hopefully) taught a lesson about double-checking what's exposed to the internet.