The U.S. Federal Trade Commission has finalized an order requiring GoDaddy to implement comprehensive security measures following multiple data breaches that occurred since 2018. The web hosting giant, which serves approximately five million customers, was found to have significant security vulnerabilities due to inadequate protective measures.
## Key Requirements of the FTC Order
GoDaddy must now:
– Establish a robust information security program
– Secure APIs using HTTPS or other secure transfer protocols
– Implement a software and firmware update management system
– Add mandatory multi-factor authentication (MFA) for all customers, employees, and contractors
– Provide at least one MFA method that doesn’t require a phone number
– Hire independent third-party assessors for biennial security reviews
– Report any data exposure incidents within 10 days
## Security Failures That Led to Breaches
The FTC’s investigation revealed that GoDaddy lacked fundamental security practices, including:
– Proper multi-factor authentication
– Adequate software update management
– Security event logging
– Network segmentation
– File integrity monitoring
– Asset management
– Risk assessment procedures
## Notable Breach Incidents
Between 2019 and 2022, GoDaddy experienced several major security breaches:
– A multi-year breach discovered in December 2022 where attackers installed malware on servers and stole source code
– A November 2021 incident where hackers accessed email addresses, WordPress admin passwords, and SSL private keys of 1.2 million Managed WordPress customers
– An October 2019 breach where attackers used hosting credentials to connect via SSH, affecting 28,000 customers
GoDaddy has stated that they have already implemented several of the required security measures and expect minimal financial impact from complying with the FTC order.
