GoDaddy told to up security practices by FTC

GoDaddy logo
(Image credit: GoDaddy)

  • FTC formally complains about GoDaddy’s security claims
  • “Major compromises” between 2019 and 2022 are the cause for concern
  • GoDaddy has reached a settlement with the FTC for better security

A new Federal Trade Commission complaint has accused GoDaddy of misleading customers and failing to protect its web hosting services sufficiently.

The notice serves as a final warning to the company, which has been told to address security concerns that date as far back as 2018, however GoDaddy isn’t set to face any immediate consequences.

The list of mistakes reportedly made by the company has now been highlighted by the FTC in an official complaint, including violations of the FTC Act.

GoDaddy gets a telling off from the FTC

The long list accuses GoDaddy of failing to: “(a) inventory and manage assets; (b) manage software updates; (c) assess risks to its website hosting services; (d) use multi-factor authentication; (e) log security-related events; (f) monitor for security threats, including by failing to use software that could actively detect threats from its many logs, and failing to use file integrity monitoring; (g) segment its network; and (h) secure connections to services that provide access to consumer data.”

In the complaint, the FTC highlights some “major compromises” between 2019 and December 2022 which involved threat actors obtaining sensitive customer information. They include attacks in October 2019, March 2020, April 2020 and November 2021.

Redirections to malicious sites, data collection, mailer script infections, database attacks, user authentication vulnerabilities, outdated plugins and code, and DDoS attacks were all highlighted as potential implications of poor security in the FTC complaint.

Consequentially, GoDaddy has agreed to a settlement in which it is prohibited from making false or misleading security claims. It must also implement an information security program, conduct regular third-party compliance assessments and report security incidents to the FTC promptly.

GoDaddy sent us the following statement:

"GoDaddy has a long history of offering innovative products to our web hosting customers. We are focused on protecting our customers’ data and websites, and we invest significant resources in technologies, tools and talent to help safeguard systems and information. We are constantly improving our security capabilities and have already implemented a number of the requirements in the settlement agreement with the FTC.

"Notably, the resolution of this matter includes no admission of fault and no monetary penalties. We expect minimal financial impact associated with complying with the terms of the agreement with the FTC. We plan to continue to invest in our defenses to address evolving threats and help keep our customers, their websites and their data safe."

You might also like

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
marriott
FTC orders Marriott and Starwood to boost cybersecurity following major incidents
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
Padlock against circuit board/cybersecurity background
Best SSL certificate service of 2025
vpn
Nominet says it was hit by cyberattack following recent Ivanti VPN security issue
Criminals are abusing top-level government domains across multiple countries
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why
Nintendo x Seattle Mariners partnership
The Nintendo Switch 2 logo will be featured on the Seattle Mariners' baseball jerseys this season
Apple iPhone 16 Pro Max Review
Siri's chances to beat ChatGPT just got a whole lot better
Acer Chromebook Plus line
Chromebooks aren't dead! Acer has just launched 7 new ChromeOS laptops aimed at students and professionals