2023 MongoDB — phishing/social engineering against corporate systems; customer account metadata exposure
Data compromised
Customer account metadata and business contact details described in MongoDB’s public incident updates—full categories vary by customer relationship
Technical writeup
MongoDB publicly confirmed unauthorized access to certain corporate applications and exposure of customer account metadata (e.g., customer contact details tied to Atlas) after a reported phishing campaign; MongoDB published follow-up summaries of containment and customer-facing guidance.
Root cause
Phishing / adversary-in-the-middle-style social engineering against workforce accounts (per MongoDB incident communications)