HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSPIILowActive
GODADDY.COM, LLC
bd_dd928eec9ec08ec9 · schema v1 · pii pii-v1
Full breach record for GODADDY.COM, LLC →GoDaddy.com, LLC disclosed a security incident affecting its Managed WordPress hosting service. An unauthorized third party gained access to authentication information (customer numbers, email addresses, and database/sFTP credentials) between September 6 and November 17, 2021. GoDaddy engaged forensic investigators, contacted law enforcement, blocked the actor, and rotated affected credentials. SSL certificates were also revoked and replaced. The incident impacts customers in multiple US states.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3e5542056436e29fWashington State AGfiled 2021-11-23(1d gap)Verified
- bd_456458c31f5bae59California State AGfiled 2021-11-23(1d gap)Verified
- bd_a6095fa3a10ef9aaMaine State AGfiled 2021-11-23(1d gap)Verified
- bd_a90e27d49b0061c6Oregon State AGfiled 2021-11-23(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 15d gap
- bd_ce4d3aa13640ac94Delaware State AGfiled 2021-11-07(15d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/12/GoDaddy-Template-Customer-Email.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2021
- Raw hash
- 832443874d614c748575fff4db90ebe7a9b422e075074f815ff8d3aaaa17bb90
Reporting entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Victim entity
- Name
- GODADDY.COM, LLCnorm: godaddycom
Incident
- Discovered
- Nov 17, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.