Burke Knight Posted February 20, 2023 Share Posted February 20, 2023 GoDaddy: Hackers stole source code, installed malware in multi-year breach Web hosting giant GoDaddy says it suffered a breach where unknown attackers have stolen source code and installed malware on its servers after breaching its cPanel shared hosting environment in a multi-year attack. While GoDaddy discovered the security breach in early December 2022 following customer reports that their sites were being used to redirect to random domains, the attackers had access to the company's network for multiple years. "Based on our investigation, we believe these incidents are part of a multi-year campaign by a sophisticated threat actor group that, among other things, installed malware on our systems and obtained pieces of code related to some services within GoDaddy," the hosting firm said in an SEC filing. The company says that previous breaches disclosed in November 2021 and March 2020 are also linked to this multi-year campaign. The November 2021 incident led to a data breach affecting 1.2 million Managed WordPress customers after attackers breached GoDaddy's WordPress hosting environment using a compromised password. They gained access to the email addresses of all impacted customers, their WordPress Admin passwords, sFTP and database credentials, and SSL private keys of a subset of active clients. After the March 2020 breach, GoDaddy alerted 28,000 customers that an attacker used their web hosting account credentials in October 2019 to connect to their hosting account via SSH. GoDaddy is now working with external cybersecurity forensics experts and law enforcement agencies worldwide as part of an ongoing investigation into the root cause of the breach. Links to attacks targeting other hosting companies GoDaddy says it also found additional evidence linking the threat actors to a broader campaign targeting other hosting companies worldwide over the years. "We have evidence, and law enforcement has confirmed, that this incident was carried out by a sophisticated and organized group targeting hosting services like GoDaddy," the hosting company said in a statement. "According to information we have received, their apparent goal is to infect websites and servers with malware for phishing campaigns, malware distribution and other malicious activities." GoDaddy is one of the largest domain registrars, and it also provides hosting services to over 20 million customers worldwide. Source: Bleeping Computer Link to comment Share on other sites More sharing options...
SpookyKipper Posted February 20, 2023 Share Posted February 20, 2023 wow, but things like this do happen sometimes. but multi year attack seems too far Link to comment Share on other sites More sharing options...
Burke Knight Posted February 20, 2023 Author Share Posted February 20, 2023 Goes to show you that they don't really make sure of their security. Just think what else they may not be admitting to... Link to comment Share on other sites More sharing options...
TinkerMan Posted February 21, 2023 Share Posted February 21, 2023 Don't use them thankfully! And now I probably never will Link to comment Share on other sites More sharing options...
Anyx Posted February 23, 2023 Share Posted February 23, 2023 (edited) Makes you wonder how many other hosting companies are affected and unaware of this... quite shocking news. I hope iFastNet's measures are keeping them safe from this. Edited February 23, 2023 by Anyx Link to comment Share on other sites More sharing options...
Agent Death Posted April 26, 2023 Share Posted April 26, 2023 well now the plan to use them is gone, but thanks for the warning @Burke Knight! Link to comment Share on other sites More sharing options...
Recommended Posts