MongoHQ Security breach
security.mongohq.com
MongoHQ Security breach
1–10 of 130 posts
Re: MongoHQ Security breach
#2Someone's updating their resume tonight.
Re: MongoHQ Security breach
#3As a precaution, we took additional steps on behalf of our customers to invalidate the Amazon Web Services credentials we were storing for you (for the purposes of backups to S3). While this prevents the abuse of your AWS credentials by any malicious party, it may have resulted in additional unintended consequences for your AWS environment if you were utilizing the same AWS credentials for other purposes.
If you had S3 backups configured with MongoHQ, when possible, we have disabled the IAM access keys via AWS. In any case, please go to the AWS Management Console and regenerate any keys given to MongoHQ .
Re: MongoHQ Security breach
#4"Our support tool includes an 'impersonate' feature that enables MongoHQ employees to access our primary web UI as if they were a logged in customer"
Re: MongoHQ Security breach
#5Other companies (looking at you Linode...) could stand to learn a thing or two from how MongoHQ is handling this. Extremely transparent, and explaining in very clear terms the steps they'll be taking to mitigate the breach and prevent future incidents.
All that being said... Ouch.
Re: MongoHQ Security breach
#6Re: MongoHQ Security breach
#7Re: MongoHQ Security breach
#8detected unauthorized access to an internal support application using a password that was shared with a compromised personal account Someone's updating their resume tonight.
In general though, in any security breach the most common way to pivot is via password re-use. You'll see this happen with many privileged employees at almost every company.
Re: MongoHQ Security breach
#9Re: MongoHQ Security breach
#10The name of this company is unfortunate. It doesn't appear that this service has any affiliation with MongoDB, Inc.