GoDaddy Security Breach Exposes 1.2 million WordPress Users' Data

GoDaddy said the incident was discovered on November 17.

Advertisement
By Reuters | Updated: 23 November 2021 10:51 IST
Highlights
  • The third-party accessed the system using a compromised password
  • The exposure of email addresses presents risk of phishing attacks
  • Up to 1.2 million Managed WordPress customers had number exposed

GoDaddy's shares fell about 1.6 percent in early trading

Web hosting company GoDaddy said on Monday email addresses of up to 1.2 million active and inactive Managed WordPress customers had been exposed in an unauthorised third-party access.

The company said the incident was discovered on November 17 and the third-party accessed the system using a compromised password.

Advertisement

"We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement," Chief Information Security Officer Demetrius Comes said in a filing.

The company, whose shares fell about 1.6 percent in early trading, said it had immediately blocked the unauthorised third party, and an investigation was still going on.

Advertisement

Here's what the company said in the filing:

On November 17, 2021, we discovered unauthorised third-party access to our Managed WordPress hosting environment. Here is the background on what happened and the steps we took, and are taking, in response:

Advertisement

We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement. Using a compromised password, an unauthorised third party accessed the provisioning system in our legacy code base for Managed WordPress.

Upon identifying this incident, we immediately blocked the unauthorised third party from our system. Our investigation is ongoing, but we have determined that, beginning on September 6, 2021, the unauthorised third party used the vulnerability to gain access to the following customer information:

Advertisement


•Up to 1.2 million active and inactive Managed WordPress customers had their email address and customer number exposed. The exposure of email addresses presents risk of phishing attacks.

•The original WordPress Admin password that was set at the time of provisioning was exposed. If those credentials were still in use, we reset those passwords.

•For active customers, sFTP and database usernames and passwords were exposed. We reset both passwords.

•For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.

Our investigation is ongoing and we are contacting all impacted customers directly with specific details. Customers can also contact us via our help centre (https://www.godaddy.com/help) which includes phone numbers based on country.

We are sincerely sorry for this incident and the concern it causes for our customers. We, GoDaddy leadership and employees, take our responsibility to protect our customers' data very seriously and never want to let them down. We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection.

Demetrius Comes
Chief Information Security Officer

© Thomson Reuters 2021


Can PUBG: New State rival BGMI and PUBG Mobile in the battle royale space? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: GoDaddy, WordPress
Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Prime Day Sale Dates Announced, Drops Prime Membership Price
  2. Oppo Reno 16 Series Will Launch in Indonesia, Malaysia on These Dates
  3. Samsung Finally Rolls Out Its Health App Update With These Features
  4. Carl Pei Tells Apple 'I'm Gonna Steal Your Customers' in Latest Video
  5. Honor 600 Smart 5G Listed on French Website, Could Launch Soon
  6. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order
  7. Vivo Y6e 5G With 6,500mAh Battery Debuts at This Price
  8. Xiaomi Wants a Bigger Space in Your Home: Large Appliance Push Confirmed
  9. Oppo Reno 15A 5G Arrives With a 7,000mAh Battery at This Price
  10. Xiaomi 17T Review
  1. Chandra Captures Sharpest-Ever X-Ray View of M87 Black Hole Jet
  2. Honor 600 Smart 5G With 7,700mAh Battery Listed on French Website, Could Launch Soon: Price, Features
  3. Rockstar Games Confirms GTA 6 Pre-Orders Will Begin June 25, Reveals New Cover Art
  4. Oppo Enco Air 5 India Launch Teased; Amazon Availability Confirmed
  5. Huawei FreeBuds 7i, FreeBuds SE 4 ANC Launched in India With Up to 50 Hours of Total Battery Life: Price, Features
  6. Aztec Hit With Second Security Breach, Days After Hackers Used Exploit to Steal $2.19 Million
  7. FilterCopy’s For The Real Me Season 1 Now on Instagram: Know Everything About This Micro-Drama Reel Series
  8. Narwal S20, S20 Pro, S30 Wet and Dry Vacuum Cleaners With Up to 20,000Pa Suction Launched in India:Price, Features
  9. Oppo Reno 16 Series Launch Date in Indonesia, Malaysia Announced as Pre-Orders Begin
  10. Vivo Y6e 5G Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.