Hundreds of Elasticsearch databases targeted in ransom attacks

By Bill Toulas, Bleeping Computer

Hackers have targeted poorly secured Elasticsearch databases and replaced 450 indexes with ransom notes asking for $620 to restore contents, amounting to a total demand of $279,000.

The threat actors set a seven-day deadline for the payments and threaten to double the demand after that. If another week passes without getting paid, they say the victim would lose the indexes.

Those who pay the amount are promised a download link to their database dump that will supposedly help restore the data structure to its original form quickly.

This campaign was discovered by threat analysts at Secureworks, who identified more than 450 individual requests for ransom payment.

According to Secureworks, the threat actors use an automated script to parse unprotected databases, wipe their data, and add the ransom, so there doesn’t appear to be any manual engagement in this operation.


Comments

Popular posts from this blog

FBI, CISA warn US hospitals of targeted BlackCat ransomware attacks

Nissan North America data breach impacts over 53,000 employees

Why Your VPN May Not Be As Secure As It Claims