GoDaddy says a multi-year breach hijacked customer websites and accounts
Three breaches over as many years all carried out by the same threat actor. GoDaddy, one of the world’s largest domain registrars, has confirmed that its network has been the victim of a sophisticated and sustained attack by unknown attackers over multiple years, resulting in the theft of company source code, customer and employee login credentials, and the installation of malware that redirected customer websites to malicious sites. The company has nearly 21 million customers and generated revenue of almost $4 billion in 2022, making it one of the most popular domain registrars globally. However, despite its popularity, the company has faced several security incidents in recent years, leading to concerns about its cybersecurity practices. In a filing with the Securities and Exchange Commission (SEC), the company reported three serious security events that started in 2020 and lasted through 2022 and were carried out by the same intruder. The most recent event occurred in December...