FTC holds GoDaddy Accountable For Misleading Claims and Inadequate Data Protection Mechanisms

The Federal Trade Commission has charged GoDaddy with inadequate cybersecurity practices and deceptive claims about data protection. Allegations include repeated breaches, weak safeguards, and failure to protect millions of users' sensitive information effectively.

FTC holds GoDaddy Accountable For Misleading Claims and Inadequate Data Protections

GoDaddy Under Fire: Federal Trade Commission Investigates Data Security Failures

The Federal Trade Commission (FTC) has filed a formal complaint against GoDaddy Inc. and its subsidiary GoDaddy.com, LLC, alleging that the website hosting giant failed to implement adequate data security measures, compromising the safety of millions of customers' data.

The complaint outlines a litany of issues, painting a picture of systemic security lapses that have plagued GoDaddy’s operations since at least 2018.

FTC Takes Action Against GoDaddy for Alleged Lax Data Security for Its Website Hosting Services
The Federal Trade Commission will require web hosting company GoDaddy to implement a robust information security program to settle charges that the company failed to secure its website-hosting serv

The Compliants: A Breach of Trust

GoDaddy, a leader in domain registration and hosting services, is accused of making misleading claims about its data security practices.

According to the FTC, GoDaddy assured customers that their websites and data were secure, while failing to implement basic safeguards such as multi-factor authentication (MFA), adequate asset tracking, and regular risk assessments.

These shortcomings exposed customers to risks including malware, unauthorised access, and stolen credentials.

The FTC's complaint specifically highlights incidents from 2019 to 2022, during which GoDaddy's systems were repeatedly compromised.

In one case, a threat actor gained access to sensitive customer data by exploiting vulnerabilities in GoDaddy’s hosting environment.

These incidents not only jeopardised website owners but also the visitors to their sites, potentially leading to identity theft, financial fraud, and other harms.

Security Failures in Detail

The FTC's filing dives deep into GoDaddy's alleged failures, painting a damning picture of negligence. Key accusations include:

  • Inadequate Monitoring: GoDaddy did not maintain consistent logging practices or implement tools to detect suspicious activity, leaving its hosting environment vulnerable to intrusions.
  • Outdated Systems: The company failed to track and update software on thousands of servers, many of which were running unsupported or end-of-life systems.
  • Weak Authentication Measures: Until 2020, administrative logins lacked MFA, and customers were not offered this option, exposing sensitive credentials to theft.
  • Lack of Risk Assessments: Despite handling sensitive customer data, GoDaddy neglected to perform regular penetration testing or assess the security implications of its hosting practices.

These lapses allowed threat actors to repeatedly infiltrate GoDaddy's systems, with one group reportedly remaining undetected for six months.

Fallout from the Breaches

The consequences of GoDaddy’s security failures have been far-reaching. Customers using GoDaddy’s shared hosting services suffered losses ranging from stolen payment details to reputational damage caused by malicious redirects.

The FTC noted that the company’s actions—or lack thereof—forced customers to spend considerable time and resources addressing these issues.

One of the most egregious breaches occurred in 2020, when attackers replaced critical server files with malicious versions, stealing credentials for nearly 28,000 accounts.

Even after discovering the breach, GoDaddy struggled to fully remediate the issue, leading to further compromises in subsequent years.

Misleading Claims

Compounding the issue, GoDaddy marketed itself as a secure and trustworthy hosting provider, claiming to monitor and protect customers around the clock.

The FTC alleges these claims were false and misled consumers into believing their data was safe.

In reality, GoDaddy's own systems were poorly secured, and its assurances of safety were nothing more than empty promises.

Settlement Order

The settlement order between the FTC and GoDaddy contains several legally binding provisions designed to address the company's data security failures and prevent future violations.

Key aspects of the settlement include:

1. Prohibition Against Misrepresentations

GoDaddy and its affiliates are prohibited from making misleading claims about the security, confidentiality, and integrity of their hosting services or the privacy measures protecting customer data.

This provision specifically targets false assurances in advertising or customer communications.

2. Mandated Information Security Programme

GoDaddy is required to implement a comprehensive, documented information security programme. This programme must:

  • Assess and mitigate internal and external risks to data security.
  • Include safeguards proportional to the volume and sensitivity of customer data.
  • Involve regular updates, testing, and monitoring to address emerging threats and vulnerabilities.

3. Independent Assessments

An independent, qualified third party must conduct biennial assessments of GoDaddy’s compliance with the order's requirements.

These assessments will verify the effectiveness of GoDaddy’s information security measures.

4. Incident Reporting and Compliance

GoDaddy must:

  • Report any data breaches to the FTC within 10 days of notifying regulatory authorities.
  • Submit annual certifications signed by a senior executive affirming compliance with the order’s provisions.
  • Maintain detailed records of compliance efforts for at least five years.

5. Record-Keeping and Monitoring

The company is obligated to retain key documents related to their security measures, customer complaints, and advertisements for inspection by the FTC.

The order also grants the FTC authority to monitor GoDaddy’s compliance through interviews, document reviews, and direct investigations.

6. Order Duration

The settlement order will remain in effect for 20 years unless extended due to future legal violations.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Technology Law.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.