HackingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryCREDENTIALSPIILowActive
GODADDY.COM, LLC
bd_456458c31f5bae59 · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →GoDaddy.com, LLC reported a security incident affecting its Managed WordPress hosting service. Between September 6-11, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database credentials. GoDaddy identified the activity on November 17, 2021, engaged forensic investigators, contacted law enforcement, blocked the intruder, and rotated affected credentials. The incident exposes customers to potential unauthorized access to their websites and phishing attacks.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3e5542056436e29fWashington State AGfiled 2021-11-23Verified
- bd_a6095fa3a10ef9aaMaine State AGfiled 2021-11-23Verified
- bd_a90e27d49b0061c6Oregon State AGfiled 2021-11-23Verified
- bd_dd928eec9ec08ec9Delaware State AGfiled 2021-11-22(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_ce4d3aa13640ac94Delaware State AGfiled 2021-11-07(16d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-547856
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 23, 2021
- Raw hash
- 11334bb39c7283238b150d9789849ce37446c45823bd998115f980984912535c
Reporting entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Victim entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Incident
- Discovered
- Nov 17, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.