shot-button
Ganesh Chaturthi Ganesh Chaturthi
Home > News > World News > Article > 12 million WordPress websites breached says GoDaddy

1.2 million WordPress websites breached, says GoDaddy

Updated on: 23 November,2021 03:35 PM IST  |  New Delhi
IANS |

In a blog post, GoDaddy's Chief Information Security Officer (CISO) Demetrius Comes said that they've discovered unauthorised access to its managed WordPress servers. The company has warned users that this exposure can put users at greater risk of phishing attacks

1.2 million WordPress websites breached, says GoDaddy

Image for representational purpose only. Photo: istock

In a huge data breach, global web hosting platform GoDaddy has revealed that nearly 1.2 million of its WordPress customers' sensitive information has been compromised.


In a blog post, GoDaddy's Chief Information Security Officer (CISO) Demetrius Comes said that they've discovered unauthorised access to its managed WordPress servers.


"Up to 1.2 million active and inactive Managed WordPress customers had their email address and customer number exposed. The exposure of email addresses presents risk of phishing attacks," Comes said late on Monday.


On November 17, the company discovered unauthorised third-party access to our Managed WordPress hosting environment.

"We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement. Using a compromised password, an unauthorised third party accessed the provisioning system in our legacy code base for Managed WordPress," the company explained.

GoDaddy has warned users that this exposure can put users at greater risk of phishing attacks.

The investigation is ongoing, but "we have determined that, beginning on September 6, 2021, the unauthorised third party used the vulnerability to gain access to the following customer information", the company informed.

The original WordPress Admin password that was set at the time of provisioning was also exposed.

"If those credentials were still in use, we reset those passwords. For active customers, sFTP and database usernames and passwords were exposed. We reset both passwords," said GoDaddy.

"We are sincerely sorry for this incident and the concern it causes for our customers. We will learn from this incident and are already taking steps to strengthen our provisioning system with additional layers of protection," said Comes.

Also Read: Connected home devices posing more hacking risks for Indian firms: Report

This story has been sourced from a third party syndicated feed, agencies. Mid-day accepts no responsibility or liability for its dependability, trustworthiness, reliability and data of the text. Mid-day management/mid-day.com reserves the sole right to alter, delete or remove (without notice) the content in its absolute discretion for any reason whatsoever.

"Exciting news! Mid-day is now on WhatsApp Channels Subscribe today by clicking the link and stay updated with the latest news!" Click here!

Register for FREE
to continue reading !

This is not a paywall.
However, your registration helps us understand your preferences better and enables us to provide insightful and credible journalism for all our readers.

Mid-Day Web Stories

Mid-Day Web Stories

This website uses cookie or similar technologies, to enhance your browsing experience and provide personalised recommendations. By continuing to use our website, you agree to our Privacy Policy and Cookie Policy. OK