The Federal Trade Commission (FTC) will require GoDaddy to implement basic security practices, such as multi-factor authentication and HTTPS APIs, as part of a settlement initiated after a series of attacks in 2018.

The FTC found that major security failures were the cause of multiple customer data breaches.
Furthermore, the company's claims of reasonable security practices allegedly misled millions of web-hosting customers, because in reality there were vulnerabilities and threats in GoDaddy's hosting environment.
See also: US Cyber Trust Mark: New security label for smart devices
“Millions of companies, especially small businesses, rely on web hosting providers like GoDaddy to secure the websites they and their customers rely on,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection.
“The FTC is acting today to ensure that companies like GoDaddy strengthen their security systems to protect consumers around the world“.
According to the complaint, GoDaddy failed to properly implement some basic security practices, such as using multi-factor authentication (MFA), managing software updates, logging security-related events, segmenting the network, and monitoring for security threats.
See also: GenAI applications in cybersecurity
The company also failed to record and manage assets, assess risks to its website hosting services, and secure connections to services that provide access to consumer data.
GoDaddy: Multiple breaches due to inadequate security practices
The FTC says that, between 2019 and 2022, the above failures led to several significant breaches, resulting in cybercriminals gaining access to websites and customer data.
For example, in February 2023, the company said that hackers stole source code and installed malware on serversafter breaching its cPanel shared hosting environment. GoDaddy discovered the breach in early December 2022 after receiving complaints from customers about their sites being compromised.
Previous breaches revealed in November 2021 and March 2020 were also linked to this campaign.
See also: New HIPAA security rule for medical data released

The November 2021 breach affected 1.2 million Managed WordPress customers.
Under a proposed settlement order, the FTC will require GoDaddy to establish a robust security program. In addition, the company will be forced to stop misleading customers about its security. Finally, GoDaddy will be required to hire an independent third-party assessor to conduct biennial reviews of its information security program.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The FTC has targeted many companies that fail to adequately protect user data in recent years. In 2023, it fined Equifax Ltd. (over £11 million) for a major data breach in 2017 , during which consumer data was stolen
Such actions send a strong message to other companies about the serious consequences of neglecting cybersecurity measures.
In light of these developments, businesses should take proactive steps to secure their online services and platforms. This includes implementing strong encryption protocols, regularly updating software and systems, and conducting regular security audits. Companies should also prioritize training their employees on best practices for safeguarding sensitive information.
Source: www.bleepingcomputer.com
