HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSPIILowActive
GODADDY.COM, LLC
bd_ce4d3aa13640ac94 · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →GoDaddy.com, LLC notified residents of 10 US states (including DE, CA, NY) of a security incident affecting its Managed WordPress hosting service. On or about September 6, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database passwords. GoDaddy blocked the actor, rotated credentials, and engaged forensic investigators and law enforcement. The incident status is active.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_dd928eec9ec08ec9Delaware State AGfiled 2021-11-22(15d gap)Verified
- bd_3e5542056436e29fWashington State AGfiled 2021-11-23(16d gap)Verified
- bd_456458c31f5bae59California State AGfiled 2021-11-23(16d gap)Verified
- bd_a6095fa3a10ef9aaMaine State AGfiled 2021-11-23(16d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_a90e27d49b0061c6Oregon State AGfiled 2021-11-23(16d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/12/GoDaddy-Template-Customer-Email.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2021
- Raw hash
- 7965058feec85327fd1ffe76a6fb50081c01a0a8a449d8309402ae9be87a3b30
Reporting entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
- Domain
- godaddy.com
Victim entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
- Domain
- godaddy.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- contacted law enforcement
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.