Domain registrar and web hosting giant GoDaddy says the recently disclosed data breach impacts several of its brands, including 123Reg, Domain Factory, Heart Internet, Host Europe, Media Temple and tsoHost.
GoDaddy revealed on November 22 that it had identified unauthorized access to its managed WordPress hosting environment. The incident resulted in the exposure of email addresses and customer numbers of as many as 1.2 million active and inactive Managed WordPress users.
Other information exposed in the breach included WordPress admin passwords set during provisioning, sFTP and database usernames and passwords, and SSL private keys.
GoDaddy systems were apparently first accessed by the hackers on September 6, but the intrusion was only discovered on November 17.
WordPress security company Defiant has learned that GoDaddy brands reselling Managed WordPress services are also affected by the incident. A majority of the impacted brands were acquired by GoDaddy in 2017 with the acquisition of Host Europe Group.
“The GoDaddy brands that resell GoDaddy Managed WordPress are 123Reg, Domain Factory, Heart Internet, Host Europe, Media Temple and tsoHost,” said Dan Rice, VP of corporate communications at GoDaddy. “A small number of active and inactive Managed WordPress users at those brands were impacted by the security incident. No other brands are impacted. Those brands have already contacted their respective customers with specific detail and recommended action.”
The impacted brands told customers that the hackers could have gained the ability to access their managed WordPress service and make changes to it, including altering the site and the content stored on it. They also warned that the compromised email addresses could be useful for phishing attacks.
Compromised credentials have been reset and users will not be able to edit the content on their websites until they set a new password.
Last year, GoDaddy notified customers of a data breach that may have resulted in their web hosting account credentials getting compromised.
Related: Hackers Trick GoDaddy Staff in Operation Targeting Cryptocurrency Services
Related: GoDaddy Notifies Customers of Data Breach
Related: Amazon S3 Bucket Exposed GoDaddy Server Information

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft
- Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking
- Google Fi Data Breach Reportedly Led to SIM Swapping
- Microsoft’s Verified Publisher Status Abused in Email Theft Campaign
- British Retailer JD Sports Discloses Data Breach Affecting 10 Million Customers
- Meta Awards $27,000 Bounty for 2FA Bypass Vulnerability
- Industry Reactions to Hive Ransomware Takedown: Feedback Friday
- US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware
Latest News
- EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft
- Malicious NPM, PyPI Packages Stealing User Information
- VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
- 98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis
- Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
- Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform
- Ransomware Leads to Nantucket Public Schools Shutdown
- Stop, Collaborate and Listen: Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing
