The Debt Collector: A MongoDB Ransom Attack in 711 Milliseconds
Our MongoDB honeypot captured a complete ransomware operation: three simultaneous connections from the same IP, systematic database enumeration, full data exfiltration, three dropDatabase commands, and a ransom note inserted into READ_ME_TO_RECOVER_YOUR_DATA. Total time on target: 711 milliseconds.

