SEC filing: a third party had access to GoDaddy's Managed WordPress hosting from September 6 to November 17, including 1.2M customer numbers and admin passwords
GoDaddy had already responded to compromised accounts by resetting passwords and removing scam-linked subdomains in 2019, while a 2020 social-engineering incident led to changed email and DNS records at crypto platforms. The Managed WordPress disclosure adds a much larger hosted-service exposure to that record.
The filing puts customer-account access, rather than only domain or DNS administration, at the center of GoDaddy's security burden. A later multiyear breach involving source code theft and server malware underscores how recurring access incidents can compound the provider's trust problem.
First-order effects
Up to 1.2 million GoDaddy Managed WordPress customers had customer numbers and admin passwords exposed during the disclosed access window, putting the affected accounts at immediate credential-security risk.
GoDaddy must account publicly for third-party access to a core managed-hosting service, adding disclosure and remediation pressure alongside the earlier account-compromise response.
Second-order effects
GoDaddy's 2019 use of password resets establishes a practical remediation precedent; customers and hosted-site operators will expect comparable account-protection measures after admin-password exposure.
The incident makes GoDaddy's control of third-party and staff access more consequential for customers whose hosting, domain, and account administration are concentrated with the same provider.
Third-order effects
Repeated disclosures spanning compromised accounts, social engineering, and managed-hosting access point to access governance becoming a durable trust differentiator among domain and hosting providers.
If breaches continue to cross account, DNS, and hosting layers, customers may place more weight on reducing the operational concentration created by relying on one provider for several web-management functions.
The trend: Managed web infrastructure is making identity and access controls a central competitive issue as providers aggregate more customer administration functions.
New: Web host GoDaddy has confirmed a data breach affecting 1.2 million customers, who use WordPress. GoDaddy said email addresses and customer IDs were accessed, and in some cases customer database passwords and SSL private keys were exposed. https://techcrunch.com/...
We've been here before... If you have an account now is the time to 1) review password/username/login details 2) keep an eye on credit, be on alert for odd spending and phishing emails, etc. 3) do you use the same password on other accounts? Change that now https://twitter.com/..…
Ruh roh - this massive breach SUCKS for GoDaddy customers, many of whom aren't all that tech savvy. Too bad @GoDaddy didn't put some of the money they received from forcing upsells on customers at every opportunity into security. https://twitter.com/...
Friends if you use Godaddy for Wordpress hosting this is extremely important information; you will want to, at minimum, rotate your SFTP password, ideally also your cert, and beyond that probably switch hosting providers https://twitter.com/...
Data breach at @GoDaddy: “The company said that active customers had their sFTP credentials (for file transfers), and the usernames and passwords for their WordPress databases, which store all the user's content, exposed in the breach.” https://twitter.com/...
I deleted my GoDaddy account a few years ago when I stoped using them. I deleted it because I figured that something like this could happen. It's nice to feel validated. https://twitter.com/...
For all GoDaddy managed WP sites. “The SEC filing indicates that the attacker had access to user email addresses and customer numbers, the original WordPress Admin password that was set at the time of provisioning, and SSL private keys.” In plain text‼️ https://www.wordfence.com/…
User data AND site data ... admin passwords for WordPress installs (!!) Expect a ton of DDOS attacks and spam email onslaughts to come out of this ... >> GoDaddy discloses recent security breach that exposed 1.2 million accounts https://www.engadget.com/...
Well, thats not good 1.2 Million accounts breached. GoDaddy filed a statement their legacy WordPress provisioning system was accessed using a compromised password So, GoDaddy does not use MFA/2FA They had access Sept 6 2021 until November 17 2021 https://www.sec.gov/... https://t…
Godaddy hacked - including admin passwords for both WordPress sites hosted on the platform, as well as passwords for sFTPs, databases and SSL private keys. https://www.sec.gov/...
No MFA at GoDaddy? “Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress.” SEC filing: https://www.sec.gov/...
Another week, another user data breach :( “Anything up to 1.2 million users have seen their email address and customer number exposed, as well as admin passwords for both WordPress sites hosted on the platform, plus passwords for sFTPs, databases and SSL private keys.” https://tw…
Hey @godaddy there is big difference between selling “hosting” and knowing @WordPress. Security of customers & their information comes first. https://www.techmeme.com/...