Just in:
Asia Responsible Enterprise Awards and Asia Pacific Enterprise Awards 2026 China Chapter Celebrate Resilient Enterprises Forging Legacies of Excellence and Impact // LG deepens Gulf streaming push with stc tv // Trump rejects Iran truce extension as Lebanon flares // Palm coolant targets Malaysia’s data centre resource strain // Building a Global EV Footprint: How VinFast and Local Partners Power Middle East Expansion // India pushes coal gasification to reduce import risks // Alpro Group and AstraZeneca Collaborate to Advance Early Detection Across the Cardio-Kidney-Metabolic Spectrum and Raise Awareness of Hyperkalemia // Annual Maintenance Contracts in Dubai: Why Property Owners Are Moving Beyond Reactive Maintenance // IHH Healthcare and Prudential Partner to Offer Policyholders More Day Surgery Care Options at Mount Elizabeth Royal Square // Warsh Fed will do nothing to derail rally in US bank shares // Coming endgame of global macro, AI bubble // Employed but stuck: Malaysia’s resilient labour market masks a career mobility gap // US emergency oil reserve sinks to 1982 low // UAE freezes trade and financial dealings with Iran // Saudi Arabia raises US Treasury holdings to $142.5bn // JSCCIB Joins Forces with Public Sector and World Bank to Launch “The Bangkok Business Summit 2026: Reinvent Thailand, Resilient ASEAN” // allnex Announces the Next SCA Capacity Investment In APAC // Hormuz shipping remains severely curtailed amid tensions // Tech Data Expands IBM Distribution to Accelerate Partner-Led Growth Across Asia Pacific // From reaction to prevention: India’s five-year turn against radicalisation //

​First came mass MongoDB ransacking: Now copycat ransoms hit Elasticsearch

1484307254 breached es

c2cp6byucaeesra.jpg

Security researcher Niall Merrigan estimates that more than 600 Elasticsearch instances have now been hit.


Image: Niall Merrigan/Twitter

Hundreds of Elasticsearch instances have been wiped in the past few hours, in near-identical ransom attacks to those that have hit more than 34,000 unsecured MongoDB databases over the past week.

Developers running Elasticsearch servers are being warned to conceal them from the web to avoid being targeted by attackers who delete data and then demand a payment to return it.

An initial report by The Register counted 360 affected Elasticsearch instances. Security researcher Niall Merrigan, who tracked the MongoDB attacks, has updated that figure to over 600 instances, most of which are hosted in the US, but also China, Europe and Singapore.

If attacks on Elasticsearch instances follow the course of the MongoDB ransacking, the number could rise quickly. John Matherly, founder of the Shodan search engine, has identified 35,000 Elasticsearch servers exposed to the internet, with most of them hosted on Amazon Web Services infrastructure.

Matherly estimated there were 99,000 MongoDB databases exposed to the web. As of Thursday, Merrigan counted 34,000 wiped MongoDB servers, resulting in several hundred terabytes of lost data.

On January 3, only 2,000 MongoDB databases had been replaced with ransom notes. Notably, attackers did not actually copy the wiped data they claimed would be returned upon payment.

Elasticsearch consultant Itamar Syn-Hershko has written a detailed post explaining how developers should configure Elastic clusters to avoid falling victim to the ransom.

Owners of hacked Elastic instances will see the message below demanding payment of 0.2 BTC ($160).

breached-es.png

This is what a typical ransom note from the Elasticsearch attackers looks like.


Image: Itamar Syn-Hershko

“Whatever you do, never expose your cluster nodes to the web. This sounds obvious, but evidently this isn’t done by all. Your cluster should never, ever be exposed to the public web,” warned Syn-Hershko.

In the past hour, Mike Paquette of Elastic’s engineering team has posted a blog explaining how to protect Elasticsearch against ransom attacks.

While the Elastic-managed version of Elasticsearch hosted on AWS is secured by default, Elasticsearch itself does not perform authentication or authorization and hence needs to be configured properly when accessible by untrusted users.

As per the company’s security advice in 2013: “Elasticsearch has no concept of a user. Essentially, anyone who can send arbitrary requests to your cluster is a super user.”

Paquette said that Elastic “strongly recommended that unsecured Elasticsearch instances should not be directly exposed to the internet”.

For Elasticsearch clusters not managed by Elastic, the company recommends taking the following steps:

  • Perform backups of all your data to a secure location and consider Curator snapshots.
  • Reconfigure your environment to run Elasticsearch on an isolated non-routable network.
  • Or if you must access the cluster over the internet, restrict access to your cluster from the internet via firewall, VPN, reverse proxy, or other technology.

Read more on security

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Coming endgame of global macro, AI bubble // Asia Responsible Enterprise Awards and Asia Pacific Enterprise Awards 2026 China Chapter Celebrate Resilient Enterprises Forging Legacies of Excellence and Impact // 2026 Taiwan Four-Season Springs Travel Campaign Officially Launches // Controller shortage puts Sydney Airport safety under scrutiny // India pushes coal gasification to reduce import risks // Annual Maintenance Contracts in Dubai: Why Property Owners Are Moving Beyond Reactive Maintenance // Beyond Applications: The Distinctive Approach to International Academic Guidance // Warsh Fed will do nothing to derail rally in US bank shares // Wiz AI agent exposes Snowflake workflow security gap // Employed but stuck: Malaysia’s resilient labour market masks a career mobility gap // Trump rejects Iran truce extension as Lebanon flares // IHH Healthcare and Prudential Partner to Offer Policyholders More Day Surgery Care Options at Mount Elizabeth Royal Square // NASA ground software flaw exposes spacecraft commands // Palm coolant targets Malaysia’s data centre resource strain // Saudi Arabia brings global water leaders to Riyadh // allnex Announces the Next SCA Capacity Investment In APAC // Tech Data Expands IBM Distribution to Accelerate Partner-Led Growth Across Asia Pacific // Alpro Group and AstraZeneca Collaborate to Advance Early Detection Across the Cardio-Kidney-Metabolic Spectrum and Raise Awareness of Hyperkalemia // tridorian launches Gemini Enterprise Experience Center in Singapore to help enterprises turn AI ambition into business outcomes // LG deepens Gulf streaming push with stc tv //