ADVERTISEMENT

GoDaddy security breach exposes 1.2 million WordPress users' data

GoDaddy hacked
Edvardas Mikalauskas
Edvardas Mikalauskas Senior Researcher
November 22, 2021 Updated: March 14, 2022 2 min read
  • Up to 1.2 million active and inactive Managed WordPress customers had their email address and customer number exposed. The exposure of email addresses presents risk of phishing attacks.
  • The original WordPress Admin password that was set at the time of provisioning was exposed. If those credentials were still in use, GoDaddy reset those passwords.
  • For active customers, sFTP and database usernames and passwords were exposed. GoDaddy reset both passwords.
  • For a subset of active customers, the SSL private key was exposed. GoDaddy are in the process of issuing and installing new certificates for those customers.
"We are sincerely sorry for this incident and the concern it causes for our customers. We, GoDaddy leadership and employees, take our responsibility to protect our customers’ data very seriously and never want to let them down. We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection."
- Demetrius Comes, Chief Information Security Officer at GoDaddy

A simple precaution against most data breaches

ADVERTISEMENT

More from CyberNews

ADVERTISEMENT