Registrar and web-hosting firm GoDaddy has disclosed that they have suffered a three-year long security breach that has facilitated cybercriminals to access their systems, activate malware and steal critical source code.
The Security Breach

The firm has stated they believe a “sophisticated and organised” group of cybercriminals has been specifically targeting hosting services.

The first hint that suggested the company had been compromised came when several GoDaddy customers complained about their websites being intermittently redirected in December 2022.

After investigating further, the company found that the issue was being caused by an unauthorised third party gaining access to their servers in their cPanel shared hosting environment, and had installed malware triggering the intermittent redirection.

While GoDaddy remediated the attack and implemented new security measures, they now believe the threat actors were accessing their networks for several years.

Previous Breaches

Breaches uncovered in March 2020 and November 2021 are now also thought to be linked to this security breach.

The breach in March 2020 involved the compromise of hosting login credentials for around 28,000 customers, alongside a number of GoDaddy personnel.

The breach in November 2021 exposed customer numbers and emails of around 1.2 million of GoDaddy’s WordPress customers.

GoDaddy is currently working with “cybersecurity experts and law enforcement agencies”, and is monitoring the activities of the cybercriminal group they believe to be responsible in order to prevent any additional cyber attacks.

The company also believes that it has evidence linking the cybercriminal group to a wider attack campaign targeting other major hosting companies over the last few years.

In their statement, they revealed:

According to information we have received, their apparent goal is to infect websites and servers with malware for phishing campaigns, malware distribution and other malicious activities.

We are using lessons from this incident to enhance the security of our systems and further protect our customers and their data.

We apologise for any inconvenience this may have caused to any of our customers or visitors to their websites.”

How does this affect you?

If you hold an account with GoDaddy and have been affected by this data breach, you should have recently received communication from the company informing you whether your data has been accessed by cybercriminals. If your data has been compromised, you will have also received further details stating how GoDaddy is remediating the incident, and offering support for any future security incidents you may encounter as a direct result of this data breach.

By implementing effective controls and achieving Cyber Essentials at either the standard or audited Cyber Essentials Plus level, combined with managed network monitoring, GoDaddy could potentially have prevented this security breach from occurring.

We all want to feel confident that we have taken appropriate measures to protect our organisation and the sensitive data that it holds, be that internal or third-party data, and this can be done most easily by certifying to the Cyber Essentials standard.

By achieving a strong basic foundation of security, such as Cyber Essentials, you can proudly declare your level of protection to stakeholders and other third parties, demonstrating that you take data compliance seriously. In the event that you become the victim of an attack, you will be better placed to defend your organisation and show that you have taken steps to protect your data, which will have a direct impact when dealing with the authorities during any subsequent investigation.

Achieving certification for Cyber Essentials is a relatively straightforward process, and as a Certification Body, TecSec Services can work with you to both implement the necessary controls and we can directly certify your organisation.

GoDaddy Data Breach

TecSec Services is an IT support and risk management provider, and we can work as your outsourced IT Provider or help supplement your internal IT function, by providing sophisticated monitoring and threat detection solutions alongside the delivery of compliance and risk management.
If you want peace of mind to know that your business is well-protected and that you have put right-sized safeguards against cyber-attacks, GDPR fines, and reputational damage in place, please contact us for a free consultation.
In addition to being a certification body, TecSec services are accredited for Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance Level 2, and UKASS accredited to ISO 27001.