close

May 2024 only! Join our Discord free of charge.

Slick­Stack
Lightning-fast WordPress on Nginx

GoDaddy had malware on their servers for years and didn’t know it

  • This topic is empty.
Viewing 9 posts - 1 through 9 (of 9 total)
  • Author
    Posts
  • #4317
    Victoria
    Guest

    just when you think GoDaddy’s reputation couldn’t get any worse, they filed a secret notice with the U.S. government that their web hosting was being exploited by hackers for YEARS and they were not even aware!

    https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/

    #4318
    Shirley
    Guest

    if I was writing a parody article about GoDaddy, I couldn’t think of a better headline

    #4319
    Debra
    Guest

    STOP USING GODADDY THERE IS NO FIXING THIS COMPANY

    #4320
    Andrew
    Guest

    https://d18rn0p25nwr6d.cloudfront.net/CIK-0001609711/e4736ddb-b4c7-485b-a8fc-1827691692c9.pdf?mc_cid=006a7961cd&mc_eid=f4391075b7

    We experience cybsersecurity incidents, and any actual or perceived breach of our security could expose us to a risk of loss or litigation and possible
    liability and subject us to regulatory or other government inquiries or investigations, which will require us to expend significant capital and other resources to
    remediate the breach, any of which would harm our business, financial condition and operating results. For examples, in March 2020, we discovered a threat
    actor compromised the hosting login credentials of approximately 28,000 hosting customers to their hosting accounts as well as the login credentials of a small
    number of our personnel. These hosting login credentials did not provide access to the hosting customers’ main GoDaddy account. We have spent resources
    investigating and responding to this activity, notified the impacted customers, reported the activity to applicable regulatory authorities, and are responding to
    requests for information regarding our data privacy and security practices, including from the Federal Trade Commission (FTC) pursuant to Civil Investigative
    Demands issued in July 2020 and October 2021. The timing of resolution and the outcome of this matter are uncertain. In November 2021, using a
    compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress (MWP), which
    impacted up to 1.2 million active and inactive MWP customers across multiple GoDaddy brands. We reported the MWP incident to applicable regulatory
    authorities and have responded to inquiries from customers, strategic partners, regulators, and the media. The timing of resolution and outcome of this matter
    are uncertain. In December 2022, an unauthorized third party gained access to and installed malware on our cPanel hosting servers. The malware intermittently
    redirected random customer websites to malicious sites. We continue to investigate the root cause of the incident. Based on our investigation, we believe these
    incidents are part of a multi-year campaign by a sophisticated threat actor group that, among other things, installed malware on our systems and obtained pieces
    of code related to some services within GoDaddy. To date, these incidents as well as other cyber threats and attacks have not resulted in any material adverse
    impact to our business or operations, but such threats are constantly evolving, increasing the difficulty of detecting and successfully defending against them. In
    case of a future incident, a history of past incidents, such as those mentioned herein, may increase the risk of higher sanctions, or that investigations into past
    incidents may be re-invigorated.

    #4321
    Michelle
    Guest

    Sucuri: claiming to protect your WordPress frontend

    GoDaddy: actually letting hackers into your hosting backend due to egregious incompetence, and then blaming it on Russia

    #4322
    Roy
    Guest
    #4330
    Joseph
    Guest

    it’s kind of sad at this point.

    #4331
    Robert
    Guest

    It sucks because Godaddy has a huge share of the domain auction market

    #4334
    Danielle
    Guest

    It sucks

    Not really, just stop using GoDaddy. There’s plenty of domains and domain marketplaces online.

Viewing 9 posts - 1 through 9 (of 9 total)
  • You must be logged in to reply to this topic.

Thanks to our generous sponsors for their support!