GODADDY.COM, LLC
bd_456458c31f5bae59 · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →5 incidents on fileGoDaddy.com, LLC notified customers of a security incident affecting Managed WordPress hosting services. On November 17, 2021, GoDaddy identified suspicious activity and engaged third-party forensics. The investigation determined that an unauthorized third party gained access to authentication information (customer numbers, email addresses, WordPress Admin logins, sFTP and database usernames/passwords) on or about September 6, 2021. GoDaddy blocked the attacker, rotated credentials, and is installing new SSL certificates. Customers are advised to reset passwords and enable MFA.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 6, 2021
Begins
Nov 17, 2021
Discovered
Nov 23, 2021
Filed
vs. sector median
18 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Washington State AGbd_3e5542056436e29f2021-11-23Verified
- Maine State AGbd_a6095fa3a10ef9aa2021-11-23Verified
- Oregon State AGbd_a90e27d49b0061c62021-11-23Verified
- Delaware State AGbd_dd928eec9ec08ec92021-11-22 · +1dVerified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- Delaware State AGbd_ce4d3aa13640ac942021-11-07 · +16dCandidate
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Nov 7 (DE), last Nov 23 (CA) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.