GoDaddy says a multi-year breach hijacked customer websites and accounts
arstechnica.com
arstechnica.com
> credentials that gave it access to a “small number” of employee accounts and the hosting accounts of roughly 28,000 customers.
> obtain login credentials for WordPress admin accounts, FTP accounts, and email addresses for 1.2 million current and inactive Managed WordPress customers
I'm curious what they concretely did:
> goal is to infect websites and servers with malware for phishing campaigns, malware distribution
> weight loss websites
but hm. I guess I don't know a lot about malware, phishing and stuff. How would you gain exactly?
If you phish someone and gain access to something, you can sell that access to someone else.
The "end" of the chain is things like ransomware, identity theft, cc fraud, etc.
Nah. The "end" of the chain is espionage, industrial or otherwise.
Multiple uses of the word “sophisticated” as if the only way someone could gain access to Godaddy for _multiple years_ was if they are quite sophisticated, and not as a result of massive negligence on the part of Godaddy itself.
No quotes from the company apologizing.
Godaddy is wild…what a mess.
Surprised they didn't come out with government state sponsored actors... Ex china, Russia , and North Korea lol(remember that excuse from sony).
Edit: to be clear, this is in no way far-fetched. Sony had terrible security and North Korea has a credible hacking capability. They mostly use it for ransomware to make cash so they can avoid sanctions, which is right in line with the activity there.
https://www.fbi.gov/news/press-releases/update-on-sony-inves...
Any idea what was the impact on Mozilla ? Did it impact the Firefox and plugin servers ?
The registrar for mozilla.org is MarkMonitor. I'd guess that most (if not all) of their big name/public facing domains are done through MarkMonitor.
Domains used for testing or marketing purposes might be done through GoDaddy and others. This is a fairly common pattern.
I would be shocked if they weren’t running afoul of GDPR required notifications by intentionally putting their heads in the sand and pretending no PII was stolen.