ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

GoDaddy Confirms Multi-Year Data Breach with Stolen Source Code and Customer Data

Hackers have managed to steal GoDaddy’s source code and customer data in a multi-year data breach that went unnoticed from 2020 to 2022, the company confirmed on Friday.

 

The web hosting giant, with 21 million customers and nearly $4 billion in revenue, revealed in a filing with the Securities and Exchange Commission that its network had been compromised in three serious security breaches. As a result, unidentified hackers stole GoDaddy’s source code, along with employee and customer login credentials.

 

This latest incident is not the first time GoDaddy has had security-related issues. In November 2021, hackers accessed 1.2 million GoDaddy customers’ accounts. Additionally, in November 2020, GoDaddy announced that its employees had been tricked by hackers into modifying the DNS settings of at least two cryptocurrency websites. In April 2020, hackers defaced Escrow.com after hacking one of GoDaddy’s employees.

 

The first incident of the recent multi-year campaign occurred in March 2020, when the attackers obtained login credentials and accessed a limited number of employee accounts and hosting accounts belonging to around 28,000 customers. The most recent invasion was noticed in December of 2022 when the attacker accessed the cPanel hosting servers. GoDaddy has reported that a sophisticated hacker group was responsible for all three incidents and that it believes that these breaches are part of a multi-year campaign.

 

The company also stated that the hackers’ primary targets were hosting services such as GoDaddy, infecting websites with malware, and launching phishing campaigns. GoDaddy has reported the incidents to the Federal Trade Commission, and law enforcement authorities have confirmed the security breaches performed by an organized and sophisticated group.

 

In response to the breaches, GoDaddy has implemented extensive security measures, including responding to subpoenas issued by the FTC. However, given that the same group has repeatedly invaded its networks and may or may not have left, it is unclear whether these measures have been successful in fully protecting the company and its customers.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543