GoDaddy, 123Reg hacked

GoDaddy, 123Reg hacked

On 22nd November 2021, GoDaddy disclosed that an unknown attacker had gained unauthorized access to the system used to provision the company’s Managed WordPress sites. The following day, GoDaddy revealed that the hack also affected their reseller brands, including 123Reg, tsoHost, Media Temple, Domain Factory, Heart Internet and Host Europe. This hack affected around 1.2M WordPress customers.

What happened?

According to GoDaddy, the attacker gained access to their system through a compromised password. They are not saying whether the password was one of their employees’ or one of their clients’. Access to this account was immediately stopped, but there was a window of about 2 months where the attacker could set up other ways to maintain access.

Now comes the juicy part – GoDaddy had been storing some login credentials in plain text, which should never be done; it’s akin to writing your PIN on the back of your credit card. So now 1.2M customers have all their WordPress websites compromised.

What could the attacker now do?


Simon Meadows

Helping ambitious entrepreneurs & full time business coaches escape the trap of growing their business whilst sacrificing time & life. Working on the elements of delivery, sales & high quality daily lead flows.

1 年

Trevor, thanks for sharing, always good to see some insights from people who have viewed my profile or are connected to me.

回复

要查看或添加评论,请登录

★ Trevor Wood ★的更多文章

  • 7 ways to improve your cybersecurity for 2022

    7 ways to improve your cybersecurity for 2022

    Over the last year we have seen a massive increase in hacking attempts on micro, small and medium-sized businesses, and…

    1 条评论
  • Facebook: how you really get hacked

    Facebook: how you really get hacked

    How people think they get hacked How they really get hacked I’ve seen loads of these types of questions on Facebook and…

  • Tips for keeping your password safe and secure

    Tips for keeping your password safe and secure

    We have loads of website we log in to these days – I have somewhere around a thousand. That’s a thousand possible…

  • Social Engineering: What is tailgating?

    Social Engineering: What is tailgating?

    What is tailgating? Tailgating (also known as piggybacking) is one of the commonest ways hackers and other mal-actors…

  • 10 keys to improve your cyber resilience

    10 keys to improve your cyber resilience

    Over the last year, more and more of us have been working from home due to the Covid-19 pandemic. With working from…

  • Social Engineering: What is quid pro quo?

    Social Engineering: What is quid pro quo?

    Quid pro quo is a Latin phrase that literally means “something for something,” or “this for that.” We use it to signify…

  • Cybersecurity: What is a honey trap?

    Cybersecurity: What is a honey trap?

    What is a honey trap? A honey trap is probably best known from the world of espionage and politics, where a person…

  • Could you be affected by diversion theft?

    Could you be affected by diversion theft?

    Diversion theft started as an “offline” attack where the mal-actor tricks a courier into picking up or dropping off a…

    1 条评论
  • 10 reasons to use a cloud backup service

    10 reasons to use a cloud backup service

    Ease of use – the simple set and forget features of the software mean that you simply choose what you want backed up…

  • What is malware?

    What is malware?

    Malware is the collective name for several different types of malicious software that are harmful to a computer user…

社区洞察

其他会员也浏览了