Cybercriminals installed malware on GoDaddy servers in a multi-year breach 

GoDaddy, a domain registrar and website building platform, suffered a multi-year breach with hackers installing malware on its servers 

February 21, 2023 01:57 pm | Updated 03:21 pm IST

GoDaddy also faced security events from 2020 to 2022, which it shared were carried out by the same attacker.

GoDaddy also faced security events from 2020 to 2022, which it shared were carried out by the same attacker. | Photo Credit: Special Arrangement

An unauthorised third party gained access to GoDaddy, a web host, domain registrar and website building platform, servers in its cPanel shared hosting environment and installed malware causing intermittent redirection of customer websites, the platform shared in a blog post.

The breach was first discovered in December 2022 after the platform investigated customer complaints about their sites being used to redirect to random domains.

The company claims that a sophisticated threat actor group, among other things, installed malware on its systems and obtained pieces of code related to some services in the Dec. 2022 attack.

The company also faced security events from 2020 to 2022, which it shared were carried out by the same attacker.

(For top technology news of the day, subscribe  to our tech newsletter Today’s Cache)

In March 2020, a threat actor compromised the hosting login credentials of approximately 28,000 hosting users to their hosting accounts as well as the login credentials of a small number of the company’s personnel. In November 2021, using a compromised password, an unauthorised third party accessed the provisioning system in the company’s legacy code which impacted up to 1.2 million active and inactive MWP customers across multiple GoDaddy brands, the company shared in a filing to the Securities and Exchange Commission (SEC).

“To date, these incidents as well as other cyber threats and attacks have not resulted in any material adverse impact to our business or operations”, the company shared.

In April 2022, research by Cybernews discovered hundreds of compromised WordPress sites running malicious phishing adverts, with GoDaddy being hit the worst with 42 infected websites.

GoDaddy currently has 1.5 million paying customers with $4 billion in revenues, according to its latest SEC filing.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.