On 22 November 2021, GoDaddy disclosed in a filing with the US Securities and Exchange Commission that an intruder had been inside its Managed WordPress hosting environment for more than ten weeks. Using a compromised password, the attacker reached the provisioning system in GoDaddy's legacy Managed WordPress code base on 6 September 2021 and was not discovered until 17 November. From that system the intruder could read email addresses and customer numbers for up to 1.2 million active and inactive customers, the original WordPress admin passwords set at provisioning, the sFTP and database usernames and passwords of active customers, and SSL private keys for a subset of active customers. Wordfence later reported that sFTP passwords had been stored in a form that could be retrieved as plain text. GoDaddy reset the passwords, began reissuing certificates and called in law enforcement. In 2023 it said the incident was connected to a multi-year campaign against its hosting business.
Key takeaways
- A single compromised password gave an intruder access to GoDaddy's Managed WordPress provisioning system from 6 September to 17 November 2021, 72 days, according to GoDaddy.
- The provisioning system held machine credentials for customer sites: sFTP and database usernames and passwords for active customers and SSL private keys for a subset of them.
- Email addresses and customer numbers for up to 1.2 million active and inactive Managed WordPress customers were exposed, and subsidiaries including 123Reg and Media Temple were also affected.
- Wordfence chief executive Mark Maunder said GoDaddy stored sFTP passwords so that plain text versions could be retrieved, rather than as hashes or public keys.
- The identity lesson: a provisioning system that keeps every site's credentials and keys in readable form turns one stolen password into a breach of every site it built.
At a glance
| Organisation | GoDaddy (Managed WordPress hosting), including the brands 123Reg, Domain Factory, Heart Internet, Host Europe, Media Temple and tsoHost |
|---|---|
| When | Unauthorised access from 6 September 2021; discovered 17 November 2021; disclosed 22 November 2021 |
| Attacker | Unnamed. In 2023 GoDaddy linked the incident to a "sophisticated and organized group targeting hosting services" |
| Entry point | A compromised password used to access the provisioning system in the legacy Managed WordPress code base |
| Identities abused | sFTP and database credentials for hosted sites, SSL/TLS private keys, original WordPress admin passwords |
| Impact | Up to 1.2 million customers' email addresses and customer numbers exposed; site credentials and some SSL private keys exposed; credentials reset and certificates reissued |
| Category | NHI. Incident class: confirmed NHI breach (site credentials and SSL private keys taken from a provisioning system) |
What happened
GoDaddy's Managed WordPress service builds and runs WordPress sites for customers. To do that, its provisioning system creates the credentials each site needs: an sFTP account for files, a database user and password, an initial WordPress admin password and, where customers buy one, an SSL certificate and its private key. GoDaddy's chief information security officer, Demetrius Comes, explained what went wrong in the statement filed with the SEC: "On November 17, 2021, we discovered unauthorized third-party access to our Managed WordPress hosting environment." He added: "Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress." GoDaddy said the access began on 6 September 2021.
The statement listed what was exposed. Email addresses and customer numbers of up to 1.2 million active and inactive customers were exposed, which Comes said "presents risk of phishing attacks". The original WordPress admin passwords were exposed, and reset where still in use. "For active customers, sFTP and database usernames and passwords were exposed," and "For a subset of active customers, the SSL private key was exposed." GoDaddy reset the sFTP and database passwords and started issuing and installing new certificates. It blocked the intruder, brought in an IT forensics firm and contacted law enforcement. GoDaddy did not say whose password was compromised, and The Hacker News noted it was unclear whether the account had two-factor authentication.
The way the credentials were stored drew criticism from Wordfence, a WordPress security firm. "GoDaddy stored sFTP passwords in such a way that the plaintext versions of the passwords could be retrieved," Wordfence chief executive Mark Maunder said, as quoted by The Hacker News, contrasting this with salted hashes or public key authentication. He also warned that "On sites where the SSL private key was exposed, it could be possible for an attacker to decrypt traffic", although that would require a man-in-the-middle position. GoDaddy later told Wordfence that a "small number of active and inactive Managed WordPress users" at its brands 123Reg, Domain Factory, Heart Internet, Host Europe, Media Temple and tsoHost were also affected.
In February 2023, GoDaddy's annual report connected the November 2021 incident with a March 2020 breach of hosting credentials and a December 2022 malware infection of its cPanel servers, attributing the campaign to a "sophisticated and organized group targeting hosting services", The Hacker News reported. GoDaddy has not named the group.
Timeline
| Date | Event |
|---|---|
| 6 September 2021 | An unauthorised party starts using a compromised password to access the Managed WordPress provisioning system. |
| 17 November 2021 | GoDaddy discovers the access and blocks the intruder. |
| 22 November 2021 | GoDaddy discloses the incident in an SEC filing and begins contacting customers. |
| 23 November 2021 | The Hacker News reports Wordfence's finding that sFTP passwords could be retrieved in plain text; GoDaddy later tells Wordfence that some customers of its other hosting brands were affected. |
| February 2023 | GoDaddy's annual report links the 2021 incident with breaches in March 2020 and December 2022. |
How it happened: the identity attack path
- Compromised password. The attacker logged in to the provisioning system in GoDaddy's legacy Managed WordPress code base with a password that had been compromised. GoDaddy has not said how, or whether it belonged to a person or a system account.
- Central store of site credentials. The provisioning system exposed the sFTP and database credentials of active sites and the original admin passwords. Wordfence says the sFTP passwords were stored so that their plain text could be retrieved.
- Private keys alongside. For a subset of active customers, the same environment exposed the SSL private keys for their sites.
- Ten weeks unnoticed. Access continued from 6 September to 17 November 2021, a period of 72 days, before GoDaddy detected it.
- Bulk reset. GoDaddy reset sFTP, database and admin passwords and began reissuing certificates for affected sites.
Impact
- Confirmed by GoDaddy: email addresses and customer numbers for up to 1.2 million active and inactive Managed WordPress customers; original WordPress admin passwords; sFTP and database usernames and passwords for active customers; SSL private keys for a subset of active customers.
- Wider brands: GoDaddy told Wordfence that a small number of Managed WordPress users at six of its other hosting brands were affected; the total was not disclosed.
- Potential: with sFTP and database access, an attacker could have read or changed site files and data, for example to plant malware or phishing pages; with SSL private keys, impersonate sites or decrypt intercepted traffic. These are risks raised by Wordfence and others, not confirmed misuse.
- Not disclosed: how the password was compromised, whose it was, and whether any customer site was altered during the 72 days.
What this means for NHI governance
The human password was only the door. What made this a large breach was what sat behind it: a provisioning system that created machine credentials for every Managed WordPress site and kept them where they could be read. sFTP accounts, database logins and TLS private keys are all non-human identities. Each belongs to a site, not a person, and each lets software authenticate without anyone present. Once an intruder could see them centrally, every site they protected was exposed, and GoDaddy had to reset them in bulk and reissue certificates.
Two lessons stand out. First, systems that create credentials should not keep readable copies of them: generate, hand over and forget, or keep secrets in a dedicated vault with its own access control and audit. Second, private keys should be generated and held where they cannot be exported, with short certificate lifetimes so that a stolen key expires quickly. Our Secrets Management Guide and Machine Identity, PKI and Certificate Lifecycle Guide cover both. The Dropbox Sign breach shows the same pattern of one back-end account exposing many customers' credentials.
Recommendations
- Do not store retrievable copies of credentials you issue. Hash passwords that only need verifying, and keep any secret that must be retrievable in a vault with separate access control. See our Secrets Management Guide.
- Protect provisioning systems as privileged infrastructure. Require phishing-resistant MFA and just-in-time access for anyone or anything that can reach them. See our Privileged Access Management Guide.
- Prefer keys over passwords for sFTP. Public key authentication means there is no reusable server-side password to steal. See our SSH Key Management Guide.
- Keep private keys non-exportable and certificates short-lived. Automate issuance and renewal so that a stolen key is useful for days, not a year. See our Machine Identity, PKI and Certificate Lifecycle Guide.
- Retire or harden legacy code paths. The intrusion went through a legacy code base; inventory old systems that still hold credentials and bring them up to current controls.
- Detect unusual access to credential stores. Alert on bulk reads of secrets and logins from new locations, so access is found in days rather than ten weeks. See our ITDR Guide.
Frequently asked questions
What happened in the GoDaddy Managed WordPress breach?
An attacker used a compromised password to access GoDaddy's Managed WordPress provisioning system from 6 September 2021 until it was discovered on 17 November 2021. Email addresses and customer numbers for up to 1.2 million customers, sFTP and database credentials, original admin passwords and some SSL private keys were exposed.
Were GoDaddy sFTP passwords stored in plain text?
Wordfence chief executive Mark Maunder said GoDaddy stored sFTP passwords in a way that let the plain text versions be retrieved, rather than as salted hashes or using public key authentication. GoDaddy's statement said the passwords were exposed and that it reset them.
What should GoDaddy Managed WordPress customers have done after the breach?
Check that GoDaddy had reset their sFTP, database and admin passwords and replaced any exposed certificate, review site files, plugins and user accounts for unexpected changes, enable two-factor authentication and watch for phishing emails that used their exposed email address and customer number.
Related NHI Mgmt Group resources
Dropbox Sign Breach 2024 · Gravity SMTP CVE-2026-4020 · Secrets Management Guide · Machine Identity, PKI and Certificate Lifecycle Guide · SSH Key Management Guide
How NHI Mgmt Group can help
Hosting and provisioning platforms create machine credentials at scale and often keep them far longer and in weaker form than they should. We help teams map where those credentials and keys are stored, who can read them and how to move to vaulted, short-lived alternatives. See our NHI and AI agent security training.
References
- GoDaddy (SEC filing): GoDaddy Announces Security Incident Affecting Managed WordPress Service (22 November 2021)
- Infosecurity Magazine: GoDaddy Announces Data Breach (22 November 2021)
- The Hacker News: GoDaddy Data Breach Exposes Over 1 Million WordPress Customers' Data (23 November 2021)
- The Hacker News: GoDaddy Discloses Multi-Year Security Breach Causing Malware Installations and Source Code Theft (18 February 2023)