MalwareBackdoorStolen CredentialsData EncryptedCustomer Data InvolvedCREDENTIALSAUTHENTICATIONLowResolved
GODADDY.COM, LLC
bd_bf9cb552a1c0179c · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →GoDaddy.com LLC notified the California AG of a security incident affecting VPS servers. Malware replaced SSH binaries, allowing unauthorized third-party remote access and capturing SSH passwords. The incident occurred in October 2019. GoDaddy eliminated the malware, reinstalled good binaries, and removed affected backups. Customers were advised to reset credentials and audit servers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566826
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2023
- Raw hash
- 5f938f70e936c59ebf51d896d7304515c58727fd2ad79d10bcbb591e7dd9cc1a
Reporting entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Victim entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSAUTHENTICATION
- Attack vector
- Unknown
- MITRE ATT&CK
- T1056 Input CaptureT1078 Valid Accounts
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.