XaiJu
dtns
dtns

patreon


Details on GoDaddy Data Breach - Threatwire

By Shannon Morse, ThreatWire

Last week GoDaddy announced via a publicized notification that data for 1.2 million customers was exposed in a data breach. This happened via GoDaddy’s Managed Wordpress hosting environment and was discovered on November 17 but according to the report, attackers had access since September 6 at least.

The attacker gained access by using a compromised password for their provisioning system in their “legacy code base for Managed Wordpress”. GoDaddy identified the breach and blocked the unauthorized third party from accessing their systems.  Impacted customers are being notified and GoDaddy hired an IT forensics firm to investigate and they contacted law enforcement to report the breach.

So what did attackers gain access to? This breach exposed 1.2 million customer email addresses and customer number, which could potentially lead to phishing attacks. It also exposed the OG WordPress Admin password set at time of provisioning, and if those passwords were still in use, they were reset by GoDaddy. For active customers, sFTP and database usernames and passwords were exposed, and the SSL private keys for a subset of those customers were also exposed. Passwords were reset by the company and new private key certificates are being issued for those affected.

Two days later, GoDaddy updated their news to add that six different Managed Wordpress service resellers were also affected by this attack, including TsoHost, Media Temple, 123Reg, Domain Factory, Heart Internet, and Host Europe. Each of these brands were also in the process of contacting affected customers.

GoDaddy Data Breach:
https://www.sec.gov/Archives/edgar/data/1609711/000160971121000122/gddyblogpostnov222021.htm
https://www.bleepingcomputer.com/news/security/godaddy-data-breach-hits-12-million-managed-wordpress-customers/
https://threatpost.com/godaddys-latest-breach-customers/176530/
https://www.wordfence.com/blog/2021/11/godaddy-tsohost-mediatemple-123reg-domain-factory-heart-internet-host-europe/


More Creators