GODADDY.COM, LLC
ent_019e5a8a935563eab3d57e5e4acff88a
Disclosures
9
State AG · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,200,000
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GODADDY.COM, LLC
- Normalized
- godaddycom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930014QNWWH8OAC930
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- GoDaddy Inc.— per SEC Exhibit 21 filing
Disclosure history (9)newest first
- 🐻California State AGas victim2023-05-17
GoDaddy.com LLC notified the California AG of a security incident affecting VPS servers. Malware replaced SSH binaries, allowing unauthorized third-party remote access and capturing SSH passwords. The incident occurred in October 2019. GoDaddy eliminated the malware, reinstalled good binaries, and removed affected backups. Customers were advised to reset credentials and audit servers.
- 🌲Washington State AGas victim2021-11-23
GoDaddy.com, LLC, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-11-17 and filed notice on 2021-11-23. 9,581 Washington residents were affected. 6 days elapsed between awareness and notification. 72 days to identify the breach.
- 🐻California State AGas victim2021-11-23
GoDaddy.com, LLC reported a security incident affecting its Managed WordPress hosting service. Between September 6-11, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database credentials. GoDaddy identified the activity on November 17, 2021, engaged forensic investigators, contacted law enforcement, blocked the intruder, and rotated affected credentials. The incident exposes customers to potential unauthorized access to their websites and phishing attacks.
- 🦞Maine State AGas victim2021-11-23
GoDaddy.com, LLC reported an external system breach that occurred in two waves, from September 6-11, 2021, and again on November 7, 2021. The breach was discovered on November 17, 2021, and affected approximately 1.2 million individuals in total, including 1,313 Maine residents. The company provided electronic notification to those affected on November 22, 2021.
- 🦫Oregon State AGas victim2021-11-23
GoDaddy.com, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-11-23. The breach occurred during 9/6/2021 - 9/11/2021, 11/7/2021 - 11/7/2021. The breach was discovered on 11/17/2021. 1,200,000 individuals were affected. Notice was sent on 11/22/2021.
- 💎Delaware State AGas victim2021-11-22
GoDaddy.com, LLC disclosed a security incident affecting its Managed WordPress hosting service. An unauthorized third party gained access to authentication information (customer numbers, email addresses, and database/sFTP credentials) between September 6 and November 17, 2021. GoDaddy engaged forensic investigators, contacted law enforcement, blocked the actor, and rotated affected credentials. SSL certificates were also revoked and replaced. The incident impacts customers in multiple US states.
- 💎Delaware State AGas victim2021-11-07
GoDaddy.com, LLC notified residents of 10 US states (including DE, CA, NY) of a security incident affecting its Managed WordPress hosting service. On or about September 6, 2021, an unauthorized third party gained access to customer authentication information, including customer numbers, email addresses, WordPress Admin logins, and database passwords. GoDaddy blocked the actor, rotated credentials, and engaged forensic investigators and law enforcement. The incident status is active.
- 🐻California State AGas victim2020-05-03
GoDaddy.com LLC reported that an unauthorized individual accessed SSH login credentials for a subset of web hosting accounts. The incident occurred on October 19, 2019. GoDaddy blocked the actor and reset affected credentials. No evidence of file modification was found. Main customer account data was not accessible.
- ⛰️New Hampshire State AGas victim2011-11-30
101domain, Inc. notified New Hampshire residents of a security breach involving a vendor's systems. A phishing attack compromised systems, potentially exposing customer personal and payment information. No direct evidence of theft was found, but unauthorized access may have occurred. The company advised customers to monitor credit reports and credit card statements.