GoDaddy Security Breach Affects 1 Million WordPress Users

Share post:

GoDaddy recently announced that it is in the midst of a major security breach that has affected the accounts of more than one million of its WordPress clients.

During the filing last Monday with the Securities and Exchange Commission, GoDaddy Chief Information Security Officer Demetrius Comes said that on November 17, 2021, the hosting company was able to detect unauthorized third-party access to its managed WordPress hosting environment.

After consulting law enforcement officers and further investigation at an IT forensics firm, GoDaddy discovered that the third party used a compromised password to gain access to the provisioning system in its legacy code base for Managed WordPress.

GoDaddy provides Managed WordPress hosting for users who want to create and manage their own WordPress blogs and websites. Simply, the “managed” part means that GoDaddy will be the one to do all the basic administrative tasks, including installing and updating WordPress and backing up hosted websites.

The breach has already led to a number of problems. First, the email addresses and customer numbers of around 1.2 million active and inactive Managed WordPress users were disclosed. Second, the original WordPress Admin passwords set at the time of deployment were also uncovered and already reset by GoDaddy.

Third, the Secure File Transfer Protocol (sFTP) and database usernames and passwords have been compromised and reset by the company. Fourth, the SSL private key has been exposed to a number of active customers, which means that the company must issue new SSL certificates for these customers.

Comes explained that GoDaddy had already blocked the third party out of its system. However, the company also found that the perpetrators had been using the compromised password since September 6, giving them more than two months to wreak havoc on the system before they were discovered.

The investigation is still ongoing. On behalf of the company, Comes has apologized for the breach and committed to improving GoDaddy’s provisioning system with more layers of protection.

However, the extent of the damage caused by this breach has yet to be assessed. Since so many accounts have been exposed, there is a very high probability that the attackers would hurry to exploit the stolen login credentials and other data to launch even more attacks

For more information, read the original story in TechRepublic.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways