Hack of GoDaddy provider, leading to the compromise of 1.2 million WordPress hosting clients

Details have emerged about the GoDaddy breach, one of the largest domain registrars and hosting providers. On November 17, traces of unauthorized access to the servers responsible for providing WordPress-based hosting (managed WordPress environments provided by the host) were discovered. An investigation into the incident revealed that outsiders accessed the WordPress hosting management system through a compromised password of one of the employees and exploited an unpatched vulnerability in the outdated system to gain access to sensitive information about 1.2 million active and inactive WordPress hosting users.

The attackers obtained data related to account usernames and passwords used by customers in the database and SFTP; the administrator passwords for each WordPress instance set during the initial creation of the hosting environment; private keys of some active users; email addresses and customer numbers that could have been used for phishing. It is noted that the attackers had access to the infrastructure starting from September 6. SSL-keys of some active users; email addresses and customer numbers that could have been used for phishing. It is noted that the attackers had access to the infrastructure starting from September 6.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster