GODADDY.COM, LLC
ent_019e5a8a935563eab3d57e5e4acff88a
Disclosures
10
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,200,000
nationwide · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GODADDY.COM, LLC
- Normalized
- godaddycom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930014QNWWH8OAC930
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- GoDaddy Inc.— per SEC Exhibit 21 filing
Disclosure history (10)newest first
- California State AGas victim2023-05-17
GoDaddy.com LLC notified the California AG of a security incident affecting VPS servers. Malware replaced SSH binaries, allowing unauthorized third-party remote access and capturing SSH passwords. The incident occurred in October 2019. GoDaddy eliminated the malware, reinstalled good binaries, and removed affected backups. Customers were advised to reset credentials and audit servers.
- Washington State AGas victim2021-11-23
GoDaddy.com, LLC reported a cybersecurity incident to Washington AG. Unauthorized access occurred starting Sept 6, 2021, via compromised credentials. Discovered Nov 17, 2021. Up to 1.2 million Managed WordPress customers affected; 9,581 in WA. Exposed data included usernames, passwords, customer numbers, emails, and SSL private keys. Notifications sent Nov 22, 2021. Investigation ongoing.
- California State AGas victim2021-11-23
GoDaddy.com, LLC notified customers of a security incident affecting Managed WordPress hosting services. On November 17, 2021, GoDaddy identified suspicious activity and engaged third-party forensics. The investigation determined that an unauthorized third party gained access to authentication information (customer numbers, email addresses, WordPress Admin logins, sFTP and database usernames/passwords) on or about September 6, 2021. GoDaddy blocked the attacker, rotated credentials, and is installing new SSL certificates. Customers are advised to reset passwords and enable MFA.
- Maine State AGas victim2021-11-23
GoDaddy.com, LLC reported an external system breach that occurred in two waves, from September 6-11, 2021, and again on November 7, 2021. The breach was discovered on November 17, 2021, and affected approximately 1.2 million individuals in total, including 1,313 Maine residents. The company provided electronic notification to those affected on November 22, 2021.
- Oregon State AGas victim2021-11-23
GoDaddy.com, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-11-23. The breach occurred during 9/6/2021 - 9/11/2021, 11/7/2021 - 11/7/2021. The breach was discovered on 11/17/2021. 1,200,000 individuals were affected. Notice was sent on 11/22/2021.
- Delaware State AGas victim2021-11-22
GoDaddy.com, LLC disclosed a security incident affecting its Managed WordPress hosting service. An unauthorized third party gained access to authentication information (customer numbers, email addresses, and database/sFTP credentials) between September 6 and November 17, 2021. GoDaddy engaged forensic investigators, contacted law enforcement, blocked the actor, and rotated affected credentials. SSL certificates were also revoked and replaced. The incident impacts customers in multiple US states.
- Delaware State AGas victim2021-11-07
GoDaddy.com, LLC notified residents of 10 US states (including DE, CA, NY) of a security incident affecting its Managed WordPress hosting service. On or about September 6, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database passwords. GoDaddy blocked the actor, rotated credentials, and engaged forensic investigators and law enforcement. The incident status is active.
- Illinois State AGas victim2021-01-01
GODADDY.COM LLC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-475). The register records the breach as discovered on September 6, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2020-05-03
GoDaddy.com LLC reported that an unauthorized individual accessed SSH login credentials for a subset of web hosting accounts. The incident occurred on October 19, 2019. GoDaddy blocked the actor and reset affected credentials. No evidence of file modification was found. Main customer account data was not accessible.
- Massachusetts State AGas victim2012-08-18
GoDaddy.com reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-08-18. 1 Massachusetts residents were affected. The report records the breach type as electronic.