FTC Orders GoDaddy to Bolster Security After Multiple Data Breaches


# FTC Orders GoDaddy to Strengthen Security Following Multiple Data Breaches

The U.S. Federal Trade Commission has finalized an order requiring GoDaddy to implement comprehensive security measures following multiple data breaches that occurred since 2018. The web hosting giant, which serves approximately five million customers, was found to have significant security vulnerabilities due to inadequate protective measures.

## Key Requirements of the FTC Order

GoDaddy must now:
– Establish a robust information security program
– Secure APIs using HTTPS or other secure transfer protocols
– Implement a software and firmware update management system
– Add mandatory multi-factor authentication (MFA) for all customers, employees, and contractors
– Provide at least one MFA method that doesn’t require a phone number
– Hire independent third-party assessors for biennial security reviews
– Report any data exposure incidents within 10 days

## Security Failures That Led to Breaches

The FTC’s investigation revealed that GoDaddy lacked fundamental security practices, including:
– Proper multi-factor authentication
– Adequate software update management
– Security event logging
– Network segmentation
– File integrity monitoring
– Asset management
– Risk assessment procedures

## Notable Breach Incidents

Between 2019 and 2022, GoDaddy experienced several major security breaches:
– A multi-year breach discovered in December 2022 where attackers installed malware on servers and stole source code
– A November 2021 incident where hackers accessed email addresses, WordPress admin passwords, and SSL private keys of 1.2 million Managed WordPress customers
– An October 2019 breach where attackers used hosting credentials to connect via SSH, affecting 28,000 customers

GoDaddy has stated that they have already implemented several of the required security measures and expect minimal financial impact from complying with the FTC order.

Share This Article