{"id":282542,"date":"2017-01-07T08:32:28","date_gmt":"2017-01-07T08:32:28","guid":{"rendered":"http:\/\/citifmonline.com\/?p=282542"},"modified":"2017-01-07T08:32:28","modified_gmt":"2017-01-07T08:32:28","slug":"web-databases-hit-in-ransom-attacks","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/","title":{"rendered":"Web databases hit in ransom attacks"},"content":{"rendered":"

Thousands of web-based databases have been deleted by cyberthieves seeking a ransom to restore the data.<\/p>\n

Gigabytes of medical, payroll and other data held in MongoDB databases have been taken by attackers, say security researchers.<\/p>\n

The systems were vulnerable to attack because their administrators accidentally left them easily accessible via the internet.<\/p>\n

Attackers are seeking small amounts of bitcoins as payment to restore data.<\/p>\n

The alarm about hackers targeting the vulnerable databases was raised by Victor Gevers – an ethical hacker who currently works for the Dutch government.<\/p>\n

Mr Gevers said the attacks started before Christmas but had accelerated once the holiday period was over. Hackers were using automated scanning tools scouring the net for the telltale signature of unsecured MongoDB systems, he said.<\/p>\n

Requests flooding in<\/strong><\/p>\n

Once they identified potential victims, attackers checked the data to see if it had any value and, if it did, deleted it and replaced it with a ransom note.<\/p>\n

Mr Gevers said he had been racing to warn administrators of vulnerable systems to turn off net access to avoid falling victim.<\/p>\n

“I am being flooded with requests for help,” he said, adding that the number of systems hit by attackers had now exceeded 5000. Victims include hospitals, small businesses and educational institutions.<\/p>\n

\"Bitcoins\"Image copyright<\/span>REUTERS<\/span><\/span>
Cyberthieves levy a ransom in bitcoins to restore stolen data<\/span><\/figcaption><\/figure>\n

Currently three separate groups appear to be targeting vulnerable MongoDB systems, according to the different ransom notes left in deleted databases. Ransom fees range from 0.2 bitcoins (\u00a3155) to 0.5 bitcoins (\u00a3390).<\/p>\n

In some cases, said Mr Gevers, attackers were simply deleting data with no intention of restoring it when the ransom was paid. He said his advice was not to pay until a firm was sure that data had been copied.<\/p>\n

Security architect Kevin Beaumont, who has also been helping vulnerable firms harden their systems against attack, said MongoDB was popular because it was free and straightforward to use.<\/p>\n

“What would have taken a database analyst and network security engineers some time to set up a few years ago takes minutes in the age of cloud computing,” he said. “It’s incredibly easy to deploy.”<\/p>\n

Mr Beaumont said MongoDB used to let anyone access it by default. That had changed in newer versions but many organisations were still running the older versions that were wide open.<\/p>\n

“While applying a password on sensitive data seems like common sense, the reality is hundreds of thousands of databases are going online without any form of security whatsoever,” he added. “This problem has been known for years and continues to grow.”<\/p>\n

–<\/p>\n

Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"

Thousands of web-based databases have been deleted by cyberthieves seeking a ransom to restore the data. Gigabytes of medical, payroll and other data held in MongoDB databases have been taken by attackers, say security researchers. The systems were vulnerable to attack because their administrators accidentally left them easily accessible via the internet. Attackers are seeking […]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[106],"tags":[],"yoast_head":"\nWeb databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Web databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"og:description\" content=\"Thousands of web-based databases have been deleted by cyberthieves seeking a ransom to restore the data. Gigabytes of medical, payroll and other data held in MongoDB databases have been taken by attackers, say security researchers. The systems were vulnerable to attack because their administrators accidentally left them easily accessible via the internet. Attackers are seeking […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/citi97.3\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-07T08:32:28+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/ichef-1.bbci.co.uk\/news\/624\/cpsprodpb\/82F8\/production\/_93282533_032734411-1.jpg\" \/>\n<meta name=\"author\" content=\"Kojo Akoto Boateng\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@citi973\" \/>\n<meta name=\"twitter:site\" content=\"@citi973\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kojo Akoto Boateng\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/\",\"url\":\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/\",\"name\":\"Web databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always\",\"isPartOf\":{\"@id\":\"https:\/\/citifmonline.com\/#website\"},\"datePublished\":\"2017-01-07T08:32:28+00:00\",\"dateModified\":\"2017-01-07T08:32:28+00:00\",\"author\":{\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\"},\"breadcrumb\":{\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citifmonline.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Web databases hit in ransom attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citifmonline.com\/#website\",\"url\":\"https:\/\/citifmonline.com\/\",\"name\":\"Citi 97.3 FM - Relevant Radio. Always\",\"description\":\"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citifmonline.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\",\"name\":\"Kojo Akoto Boateng\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"caption\":\"Kojo Akoto Boateng\"},\"url\":\"https:\/\/citifmonline.com\/author\/kojo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Web databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Web databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always","og_description":"Thousands of web-based databases have been deleted by cyberthieves seeking a ransom to restore the data. Gigabytes of medical, payroll and other data held in MongoDB databases have been taken by attackers, say security researchers. The systems were vulnerable to attack because their administrators accidentally left them easily accessible via the internet. Attackers are seeking […]","og_url":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/","og_site_name":"Citi 97.3 FM - Relevant Radio. Always","article_publisher":"https:\/\/www.facebook.com\/citi97.3","article_published_time":"2017-01-07T08:32:28+00:00","og_image":[{"url":"http:\/\/ichef-1.bbci.co.uk\/news\/624\/cpsprodpb\/82F8\/production\/_93282533_032734411-1.jpg"}],"author":"Kojo Akoto Boateng","twitter_card":"summary_large_image","twitter_creator":"@citi973","twitter_site":"@citi973","twitter_misc":{"Written by":"Kojo Akoto Boateng","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/","url":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/","name":"Web databases hit in ransom attacks - Citi 97.3 FM - Relevant Radio. Always","isPartOf":{"@id":"https:\/\/citifmonline.com\/#website"},"datePublished":"2017-01-07T08:32:28+00:00","dateModified":"2017-01-07T08:32:28+00:00","author":{"@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1"},"breadcrumb":{"@id":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/citifmonline.com\/2017\/01\/web-databases-hit-in-ransom-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citifmonline.com\/"},{"@type":"ListItem","position":2,"name":"Web databases hit in ransom attacks"}]},{"@type":"WebSite","@id":"https:\/\/citifmonline.com\/#website","url":"https:\/\/citifmonline.com\/","name":"Citi 97.3 FM - Relevant Radio. Always","description":"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citifmonline.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1","name":"Kojo Akoto Boateng","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","caption":"Kojo Akoto Boateng"},"url":"https:\/\/citifmonline.com\/author\/kojo\/"}]}},"_links":{"self":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/282542"}],"collection":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/comments?post=282542"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/282542\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/media?parent=282542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/categories?post=282542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/tags?post=282542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}