/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GoDaddy discovered a multiyear security breach in early December 2022 in which unknown attackers stole some source code and installed malware on its servers

Web hosting giant GoDaddy says they suffered a breach where unknown attackers have stolen source code and installed malware …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

GoDaddy’s disclosure follows a 2021 Managed WordPress compromise that exposed customer numbers and administrator passwords, as well as a 2020 social-engineering incident tied to changes in email and DNS records for crypto platforms. The new report extends the company’s security record from account-level and administrative access problems to attackers operating on its servers and taking source code.

That history matters because GoDaddy is both a hosting provider and a domain-management intermediary: a server compromise can affect confidence in the operational layers customers use to run sites, not merely individual account credentials.

First-order effects

  • GoDaddy must contain the malware, determine which servers and source code were affected, and assess whether its hosting customers’ services or data were exposed during the multiyear intrusion.
  • Customers using GoDaddy’s hosting infrastructure face a renewed need to review their own sites, credentials, and service dependencies against an incident that involved the provider’s servers.

Second-order effects

  • Squarespace, Wix, and other website-platform competitors gain a security-positioning opening as prospective customers weigh the resilience and transparency of their hosting providers.
  • The incident raises the value of tighter monitoring and access controls across GoDaddy’s hosting environment, particularly after the earlier Managed WordPress access breach showed that privileged platform access can reach customer administration.

Third-order effects

  • Repeated incidents across accounts, DNS administration, and servers point to security becoming a core product differentiator for web-platform providers, rather than a back-office compliance function.
  • If providers increasingly treat hosting, domain controls, and software delivery as one attack surface, the market will favor more integrated [[a:software-delivery-control-plane|software-delivery control planes]] and ecosystem-wide incident defenses.

The trend: Web-platform competition is broadening from site-building features and pricing toward demonstrable control of the shared infrastructure on which customers depend.

Discussion

  • @serghei@mastodon.social Sergiu Gatlan on mastodon
    GoDaddy says it suffered a breach where unknown attackers have stolen source code and installed malware on its servers after breaching its cPanel shared hosting environment in a multi-year attack. …
  • @thezedwards @thezedwards on x
    Thank god @godaddy has finally admitted this! I did research on this for a long ass time, and was the first to point out that some of their infrastructure seemed to be compromised: https://victorymedium.com/... https://twitter.com/...
  • @seanwrightsec Sean Wright on x
    Next big company to suffer a breach and have its source code stolen. Also worth noting they knew about this at the beginning of December last year and only informing about it now! https://www.bleepingcomputer.com/ ...
  • @ax_sharma Ax Sharma on x
    “While GoDaddy discovered the security breach following customer reports in early December 2022 that their sites were being used to redirect to random domains, the attackers had access to the company's network for multiple years.” 😬 via @serghei https://www.bleepingcomputer.com/ …
  • @bleepincomputer @bleepincomputer on x
    SCOOP: GoDaddy says unknown threat actors have installed malware on its hosting servers and stolen source code after breaching its cPanel shared environment - @serghei https://www.bleepingcomputer.com/ ...