GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches'
ID: 431ffc25-2550-52af-b7b7-8093cd1e72d2
STIX ID: report--431ffc25-2550-52af-b7b7-8093cd1e72d2
Feed Name: The Register (Security)
The FTC filed a complaint alleging GoDaddy failed to implement basic security controls (asset management, patching, MFA, SIEM, logging, network segmentation, secure connections) across its hosting environment since 2018, citing repeated compromises between 2019 and 2022. A proposed settlement requires GoDaddy to establish a comprehensive security program—including centralized inventory, near-real-time event analysis, audit logging, HTTPS for APIs, and MFA for all relevant access—while prohibiting misrepresentations about security; no immediate fine is imposed, but non-compliance could trigger significant penalties.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
