← MongoDB

2023 MongoDB — phishing/social engineering against corporate systems; customer account metadata exposure

2023 Unknown records affected Share on X

Data compromised

Customer account metadata and business contact details described in MongoDB’s public incident updates—full categories vary by customer relationship

Technical writeup

MongoDB publicly confirmed unauthorized access to certain corporate applications and exposure of customer account metadata (e.g., customer contact details tied to Atlas) after a reported phishing campaign; MongoDB published follow-up summaries of containment and customer-facing guidance.

Root cause

Phishing / adversary-in-the-middle-style social engineering against workforce accounts (per MongoDB incident communications)

References