/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

SEC filing: a third party had access to GoDaddy's Managed WordPress hosting from September 6 to November 17, including 1.2M customer numbers and admin passwords

Daniel Cooper / Engadget :

Engadget Daniel Cooper

Context & Ripple Effects

GoDaddy had already responded to compromised accounts by resetting passwords and removing scam-linked subdomains in 2019, while a 2020 social-engineering incident led to changed email and DNS records at crypto platforms. The Managed WordPress disclosure adds a much larger hosted-service exposure to that record.

The filing puts customer-account access, rather than only domain or DNS administration, at the center of GoDaddy's security burden. A later multiyear breach involving source code theft and server malware underscores how recurring access incidents can compound the provider's trust problem.

First-order effects

  • Up to 1.2 million GoDaddy Managed WordPress customers had customer numbers and admin passwords exposed during the disclosed access window, putting the affected accounts at immediate credential-security risk.
  • GoDaddy must account publicly for third-party access to a core managed-hosting service, adding disclosure and remediation pressure alongside the earlier account-compromise response.

Second-order effects

  • GoDaddy's 2019 use of password resets establishes a practical remediation precedent; customers and hosted-site operators will expect comparable account-protection measures after admin-password exposure.
  • The incident makes GoDaddy's control of third-party and staff access more consequential for customers whose hosting, domain, and account administration are concentrated with the same provider.

Third-order effects

  • Repeated disclosures spanning compromised accounts, social engineering, and managed-hosting access point to access governance becoming a durable trust differentiator among domain and hosting providers.
  • If breaches continue to cross account, DNS, and hosting layers, customers may place more weight on reducing the operational concentration created by relying on one provider for several web-management functions.

The trend: Managed web infrastructure is making identity and access controls a central competitive issue as providers aggregate more customer administration functions.

Discussion

  • @zackwhittaker Zack Whittaker on x
    New: Web host GoDaddy has confirmed a data breach affecting 1.2 million customers, who use WordPress. GoDaddy said email addresses and customer IDs were accessed, and in some cases customer database passwords and SSL private keys were exposed. https://techcrunch.com/...
  • @wolven @wolven on x
    Well shit. That sounds pretty fcking bad https://twitter.com/...
  • @takarasmall Takara Small on x
    We've been here before... If you have an account now is the time to 1) review password/username/login details 2) keep an eye on credit, be on alert for odd spending and phishing emails, etc. 3) do you use the same password on other accounts? Change that now https://twitter.com/..…
  • @crosstalksol Crosstalk Solutions on x
    Ruh roh - this massive breach SUCKS for GoDaddy customers, many of whom aren't all that tech savvy. Too bad @GoDaddy didn't put some of the money they received from forcing upsells on customers at every opportunity into security. https://twitter.com/...
  • @kevinriggle Kevin Riggle on x
    Friends if you use Godaddy for Wordpress hosting this is extremely important information; you will want to, at minimum, rotate your SFTP password, ideally also your cert, and beyond that probably switch hosting providers https://twitter.com/...
  • @troyhunt Troy Hunt on x
    Data breach at @GoDaddy: “The company said that active customers had their sFTP credentials (for file transfers), and the usernames and passwords for their WordPress databases, which store all the user's content, exposed in the breach.” https://twitter.com/...
  • @willcaruana @willcaruana on x
    I deleted my GoDaddy account a few years ago when I stoped using them. I deleted it because I figured that something like this could happen. It's nice to feel validated. https://twitter.com/...
  • @samwcyo Sam Curry on x
    Not saying this was expected, but I haven't exactly heard anything positive about working with their security team... https://twitter.com/...
  • @marie_haynes Marie Haynes on x
    For all GoDaddy managed WP sites. “The SEC filing indicates that the attacker had access to user email addresses and customer numbers, the original WordPress Admin password that was set at the time of provisioning, and SSL private keys.” In plain text‼️ https://www.wordfence.com/…
  • @johnkoetsier John Koetsier on x
    User data AND site data ... admin passwords for WordPress installs (!!) Expect a ton of DDOS attacks and spam email onslaughts to come out of this ... >> GoDaddy discloses recent security breach that exposed 1.2 million accounts https://www.engadget.com/...
  • @jmcmurry James McMurry on x
    Well, thats not good 1.2 Million accounts breached. GoDaddy filed a statement their legacy WordPress provisioning system was accessed using a compromised password So, GoDaddy does not use MFA/2FA They had access Sept 6 2021 until November 17 2021 https://www.sec.gov/... https://t…
  • @_r_netsec @_r_netsec on x
    Godaddy hacked - including admin passwords for both WordPress sites hosted on the platform, as well as passwords for sFTPs, databases and SSL private keys. https://www.sec.gov/...
  • @ryanaraine Ryan Naraine on x
    No MFA at GoDaddy? “Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress.” SEC filing: https://www.sec.gov/...
  • @mooreds Dan Moore on x
    Another week, another user data breach :( “Anything up to 1.2 million users have seen their email address and customer number exposed, as well as admin passwords for both WordPress sites hosted on the platform, plus passwords for sFTPs, databases and SSL private keys.” https://tw…
  • @quinnypig Corey Quinn on x
    NoDaddy! https://twitter.com/...
  • @om @om on x
    Hey @godaddy there is big difference between selling “hosting” and knowing @WordPress. Security of customers & their information comes first. https://www.techmeme.com/...