GoDaddy
Disclosed Jan 15, 20251 year agoSettled
Repeated hosting breaches since 2018 led to FTC data security order
The FTC alleged that since 2018 GoDaddy failed to inventory assets, patch, log and segment its shared hosting environment, leading to several major security breaches, while misleading customers about its protections. Its order, finalized in May 2025, requires a comprehensive information security program.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jan 15, 2025 |
| Attack | Hacking |
| Data exposed | Credentials and tokens, Other |
| Sector | Tech · US |
| Status | Settled |
| Lawsuit or fine | FTC consent order (proposed Jan 2025, finalized May 2025); no monetary penalty |
Sources
| Source | |
|---|---|
| FTC Takes Action Against GoDaddy for Alleged Lax Data Securityftc.gov · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jan 15, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.