GoDaddy, the world’s largest domain and web hosting company that serves approximately 20 million customers worldwide, has notified some of its customers that an unauthorized party used their web hosting account credentials to log in to their hosting accounts via SSH. The breach appears to have occurred on October 19, 2019, after security detected suspicious activity on servers . Specifically, GoDaddy, after conducting an investigation into the breach, sent a letter to its affected customers. The letter informed its customers that after an investigation, the company discovered that an unauthorized person had access to their login credentials used to log in to their hosting accounts via SSH. However, the company noted that it has not yet found evidence that any files were added or modified by the attackers in the affected hosting accounts during the breach. The company also assured users that only their hosting accounts were affected as part of the security incident, and the attackers did not have access to their main GoDaddy account. It also added that the company's team has proactively reset the login details of the affected users' hosting accounts in an effort to prevent any potential unauthorized access, recommending that customers check their hosting accounts to make sure everything is in order.

While there is no clear statement about why this security incident occurred, GoDaddy’s message and free service offer suggest that this was not due to customer error. Specifically, the company said that it is offering its customers a free year of Website Security Deluxe and Malware , services that run scans on their website and alert them to any security flaws. In the event that an error or any other suspicious activity is detected, customers will contact the company directly, which will take the necessary action.

This is not the first time GoDaddy has been hit by a security incident. Last year, hackers compromised hundreds of the company’s accounts to create 15,000 subdomains, some of which attempted to spoof popular websites to redirect targeted victims to spammy pages. GoDaddy was also found to be injecting JavaScript into its US customers’ websites without their knowledge, potentially rendering them inoperable or affecting their overall performance. This appears to be linked to website tracking and the collection of data about connection time and page load times, called real user metrics (RUM), from US customers using cPanel Shared Hosting or cPanel Business hosting.
