Watch out - your unsecured database might be about to get 'meowed'

Best cloud databases
(Image credit: Pixabay)

Unsecured databases exposed on the public web are once again being targeted but this time they're falling victim to automated 'meow' attacks that wipe their data without any explanation or even a ransom note.

This new wave of attacks began recently and both Elasticsearch and MongoDB instances are being targeted by an unknown attacker. Security researchers have responded accordingly and they're now on the lookout for exposed databases so that they can warn their owners before they become 'meowed'.

The Hong Kong-based VPN provider UFO VPN is the most recent example of a company whose Elasticsearch database was hit by a meow attack. Comparitech's Bob Diachenko first discovered the unsecured database at the beginning of July and warned the company about it. 

UFO VPN then took steps to secure its database. However, just five days later the data became exposed again. It was then that the database got 'meowed' and almost all of the records it contained were wiped.

Meow attacks

These new 'meow' database attacks were first observed by researchers only a few days ago. As of now, it is still unclear as to whether these attacks were launched by a hacker trying to hurt companies that failed to secure their databases or a vigilante who is trying to teach them a lesson. Either way 'meow' attacks are very serious and businesses hit by them stand to lose all of their unsecured data.

In addition to Diachenko, chairman of the non-profit GDI Foundation Victor Gevers has also observed these kinds of attacks in the wild. Gevers told BleepingComputer that the actor behind the attacks is also targeting exposed MongoDB databases and trying to wipe as many as they can.

While data leaks from unsecured Elasticsearch and MongoDB instances on the public web have declined in recent years as database owners have taken steps to better secure their data, there is still a great deal of sensitive information currently exposed online.

If you or your businesses has a database online, it is essential that you take steps immediately to make sure that your database is secured to prevent falling victim to a 'meow' attack. 

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why