Search

GoDaddy Security Breach Exposes 1.2 million WordPress Users' Data

GoDaddy said the incident was discovered on November 17.

Advertisement
Highlights
  • The third-party accessed the system using a compromised password
  • The exposure of email addresses presents risk of phishing attacks
  • Up to 1.2 million Managed WordPress customers had number exposed
GoDaddy Security Breach Exposes 1.2 million WordPress Users' Data

GoDaddy's shares fell about 1.6 percent in early trading

Web hosting company GoDaddy said on Monday email addresses of up to 1.2 million active and inactive Managed WordPress customers had been exposed in an unauthorised third-party access.

The company said the incident was discovered on November 17 and the third-party accessed the system using a compromised password.

"We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement," Chief Information Security Officer Demetrius Comes said in a filing.

The company, whose shares fell about 1.6 percent in early trading, said it had immediately blocked the unauthorised third party, and an investigation was still going on.

Here's what the company said in the filing:

On November 17, 2021, we discovered unauthorised third-party access to our Managed WordPress hosting environment. Here is the background on what happened and the steps we took, and are taking, in response:

We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement. Using a compromised password, an unauthorised third party accessed the provisioning system in our legacy code base for Managed WordPress.

Upon identifying this incident, we immediately blocked the unauthorised third party from our system. Our investigation is ongoing, but we have determined that, beginning on September 6, 2021, the unauthorised third party used the vulnerability to gain access to the following customer information:


•Up to 1.2 million active and inactive Managed WordPress customers had their email address and customer number exposed. The exposure of email addresses presents risk of phishing attacks.

•The original WordPress Admin password that was set at the time of provisioning was exposed. If those credentials were still in use, we reset those passwords.

•For active customers, sFTP and database usernames and passwords were exposed. We reset both passwords.

•For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.

Our investigation is ongoing and we are contacting all impacted customers directly with specific details. Customers can also contact us via our help centre (https://www.godaddy.com/help) which includes phone numbers based on country.

We are sincerely sorry for this incident and the concern it causes for our customers. We, GoDaddy leadership and employees, take our responsibility to protect our customers' data very seriously and never want to let them down. We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection.

Demetrius Comes
Chief Information Security Officer

© Thomson Reuters 2021


Can PUBG: New State rival BGMI and PUBG Mobile in the battle royale space? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: GoDaddy, WordPress
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Shark 5G India Launch Date, Price Range, Key Features Revealed
  2. Samsung Galaxy S25 Gets Upgrade Bonus and Cashback Offers in India
  3. Oppo Reno 14 5G, Reno 14 Pro 5G With 50-Megapixel Selfie Cameras Launched
  4. Vivo V50 Elite Edition Launched in India; Vivo TWS 3e Included in the Box
  5. OTT Releases This Week: Bhool Chuk Maaf, Wolf Man, Maranammas, and More
  6. 20th Anniversary iPhone Said to Get a Bezel-Free Design and More
  1. SpaceX Fires Up Starship Upper Stage for Ninth Test Flight in Static Fire Trial
  2. Hikers Stumble Upon 600 Gold Coins in Czech Forest Near Polish Border
  3. NASA’s IMAP Spacecraft Prepares to Map the Solar System’s Edge
  4. Hubble Captures First-Ever Rogue Black Hole Devouring a Star Outside Galactic Core
  5. SpaceX Launches 28 Starlink Satellites from Florida: What You Need to Know
  6. Lava Shark 5G India Launch Set for May 23; to Be Priced Under Rs 10,000
  7. Alcatel V3 Ultra Price Range Tipped; May Launch Alongside Alcatel V3 Pro, V3 Classic
  8. Google Gemini Advanced Users Can Now Connect the Chatbot With GitHub
  9. US President Donald Trump Asks Apple to Stop Moving iPhone Production to India
  10. Coinbase Says Cybercriminals Breached User Data, Demanded $20 Million Ransom
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »