Article Details

Scrape Timestamp (UTC): 2023-12-17 04:57:24.788

Source: https://thehackernews.com/2023/12/mongodb-suffers-security-breach.html

Original Article Text

Click to Toggle View

MongoDB Suffers Security Breach, Exposing Customer Data. MongoDB on Saturday disclosed it's actively investigating a security incident that has led to unauthorized access to "certain" corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident response efforts. It further noted that "this unauthorized access has been going on for some period of time before discovery," but emphasized it's not "aware of any exposure to the data that customers store in MongoDB Atlas. It did not disclose the exact time period of the compromise. In light of the breach, MongoDB recommends that all customers be on the lookout for social engineering and phishing attacks, enforce phishing-resistant multi-factor authentication (MFA), as well as rotate their MongoDB Atlas passwords. That's not all. The company said it's also experiencing elevated login attempts that are causing issues for customers attempting to log in to Atlas and our Support Portal. It, however, said the problem is unrelated to the security event. The Hacker News has reached out to MongoDB for additional comments, and we will update the story if we hear back. (This is a developing story. Please check back for more updates.)

Daily Brief Summary

DATA BREACH // MongoDB Security Incident Exposes Customer Account Metadata

MongoDB disclosed an active investigation into unauthorized access of their corporate systems, leading to the exposure of customer data.

The security breach was detected on December 13, 2023, upon which immediate incident response procedures were initiated.

No evidence was provided stating that customer data stored in MongoDB Atlas was exposed during the unauthorized access.

The specific duration of the breach remains undisclosed, but the access was noted to have occurred over an unspecified period prior to detection.

MongoDB has issued a warning to customers to be vigilant against potential phishing attacks and to implement phishing-resistant multi-factor authentication (MFA).

Users are also advised to change their MongoDB Atlas account passwords as a precautionary measure.

The company is currently facing increased login attempts that are impacting user ability to access the Atlas platform and Support Portal, which are stated to be unrelated to the breach.