GODADDY.COM, LLC
bd_ce4d3aa13640ac94 · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →5 incidents on fileGoDaddy.com, LLC notified residents of 10 US states (including DE, CA, NY) of a security incident affecting its Managed WordPress hosting service. On or about September 6, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database passwords. GoDaddy blocked the actor, rotated credentials, and engaged forensic investigators and law enforcement. The incident status is active.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 6, 2021
Begins
Nov 7, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Delaware State AGbd_dd928eec9ec08ec92021-11-22 · +15dVerified
- Washington State AGbd_3e5542056436e29f2021-11-23 · +16dVerified
- California State AGbd_456458c31f5bae592021-11-23 · +16dVerified
- Maine State AGbd_a6095fa3a10ef9aa2021-11-23 · +16dVerified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- Oregon State AGbd_a90e27d49b0061c62021-11-23 · +16dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Nov 7 (DE), last Nov 23 (OR) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.