GoDaddy is the world's largest domain registrar and hosting provider, serving more than 20 million customers. But that scale also makes it an attractive target for attackers — and the record shows those attackers have succeeded more than once. Hosting your site with a big company does not automatically mean you are secure.
This guide summarizes GoDaddy's most significant security incidents, what information was exposed, and the concrete steps you can take today to lower your risk.
GoDaddy's Most Serious Security Incidents
GoDaddy has disclosed at least three large-scale security breaches to the U.S. Securities and Exchange Commission (SEC) and to its own customers. Understanding them in chronological order reveals a troubling pattern.
2019: SSH credentials exposed
In October 2019, an attacker accessed the SSH credentials of approximately 28,000 hosting accounts. GoDaddy took several months to detect the intrusion. SSH access gave the attacker full control over the files of affected accounts.
2021: 1.2 million WordPress accounts compromised
This remains the most serious incident to date. An attacker used a compromised password to access GoDaddy's Managed WordPress provisioning system. The outcome:
- Email addresses and customer numbers of 1.2 million active and inactive users were exposed.
- Original WordPress admin passwords, sFTP credentials, and database passwords were leaked.
- Private SSL keys for a subset of active customers were accessible.
The attacker had access for two months before GoDaddy detected the breach.
2022–2023: persistent malware campaign
In its 2022 annual report (10-K) filed with the SEC, GoDaddy revealed that the 2021 and earlier incidents were part of a campaign orchestrated by a sophisticated threat group. This group installed malware on GoDaddy's shared servers and stole source code fragments. The full scope of the campaign took years to uncover.
What Types of Data Are at Risk
The incidents above exposed different categories of information. If you are a GoDaddy customer, here is what an attacker could have obtained — or could obtain in a future breach:
| Data type | Potential risk |
|---|---|
| Account email address | Targeted phishing, identity impersonation |
| sFTP / SSH credentials | Full access to website files |
| Database password | Data theft or modification |
| WordPress admin password | CMS takeover, malware injection |
| Private SSL key | Encrypted traffic interception (MITM) |
Why Shared Hosting Amplifies the Risks
Most GoDaddy customers use shared hosting: multiple websites coexist on the same physical server. This creates additional attack surfaces beyond the corporate breach itself:
- Cross-contamination: if a neighboring site on the same server is compromised with malware, that malware may attempt to spread to other accounts.
- Shared resources: CPU and memory saturated by a DDoS attack on a neighbor affects your site's availability.
- Outdated PHP versions: GoDaddy has historically offered unsupported PHP versions as options, leaving unsuspecting customers exposed to known vulnerabilities.
These issues are not unique to GoDaddy — they are inherent to the shared model — but they are more acute when the provider has a track record of infrastructure intrusions. If you are looking for a more security-conscious alternative, the team at elenlace.com can guide you toward safer hosting options for the Mexican market.
Common Mistakes GoDaddy Users Make
Beyond the provider's own failures, users often make mistakes that increase their exposure:
- Reusing the same password across GoDaddy, WordPress, and corporate email. If one leaks, all fall.
- Not enabling two-factor authentication (2FA) on the GoDaddy account. The panel supports it; few users turn it on.
- Ignoring GoDaddy alerts. After the 2021 breach, GoDaddy emailed affected customers — many treated it as spam and never changed their passwords.
- Not keeping independent backups. Relying solely on GoDaddy's backups means a compromised account may also mean compromised backups.
- Leaving WordPress plugins outdated. An unpatched WordPress installation is the most common malware entry point in shared hosting.
How to Protect Yourself If You Use GoDaddy
If you decide to stay with GoDaddy — or simply cannot migrate right away — the following actions meaningfully reduce your exposure:
1. Enable 2FA on your GoDaddy account
Go to Account Settings → Two-Step Authentication and link an authenticator app (Google Authenticator, Authy). This blocks access even if your password is compromised.
2. Change all associated credentials
Generate unique passwords for: your GoDaddy account, WordPress admin, database, and sFTP. Use a password manager (Bitwarden, 1Password) — never reuse anything.
3. Install a WordPress security plugin
Wordfence Security (free tier) or Solid Security (formerly iThemes Security) provide:
- Malware scanning of site files.
- Brute-force login blocking.
- Alerts for changes to core WordPress files.
4. Set up external, independent backups
Use UpdraftPlus with a Google Drive or Dropbox destination. Schedule daily database backups and weekly full-file backups. The backup must live outside GoDaddy's infrastructure.
5. Renew or revoke your SSL certificate if you were affected
If you received a GoDaddy notification about the 2021 breach, request a new SSL certificate from your control panel. If GoDaddy already reissued one automatically, verify the issuance date.
6. Keep WordPress, themes, and plugins updated
Enable automatic updates for at least WordPress core security releases. Remove plugins you no longer use — every inactive plugin is a potential attack surface.
When Does It Make Sense to Switch Providers?
The steps above reduce risk but do not eliminate the structural vulnerabilities of mass shared hosting. Consider migrating when:
- Your site handles sensitive data (payments, health information, minors' data).
- A few hours of downtime costs you measurable revenue or clients.
- You need to comply with PCI-DSS or Mexico's Federal Law on Personal Data Protection (LFPDPPP).
- You have suffered a malware infection — reinfection in the same compromised environment is common.
There are hosting alternatives in Mexico and Latin America with more modern infrastructure and stronger security practices. Browse our hosting comparison section to find the option that best fits your project.
Key Takeaways
- GoDaddy has suffered at least three significant security breaches between 2019 and 2023, part of an organized campaign by a sophisticated threat group.
- Exposed data includes emails, SSH credentials, WordPress passwords, database credentials, and private SSL keys.
- Shared hosting amplifies risks: cross-contamination, malicious neighbors, and outdated software versions.
- Enabling 2FA, changing all credentials, and setting up external backups are the most urgent actions to take.
- If your site handles sensitive data or transactions, evaluating an alternative provider is a sound business decision, not an overreaction.
If you are unsure which hosting provider matches your risk tolerance and budget, elenlace.com offers free hosting consulting for businesses and projects in Mexico — we help you compare options with no commitment.
FAQ
Should I change my GoDaddy password even if I wasn't notified about a breach?
Yes. GoDaddy's notifications cover customers who may have been directly affected, but they do not guarantee that every exposed user was notified. Changing passwords and enabling 2FA is a low-cost, high-impact preventive measure.
Is GoDaddy's SSL certificate still trustworthy after the 2021 breach?
SSL certificates themselves are secure as long as the private key has not been compromised. After the 2021 breach, GoDaddy was required to revoke and reissue affected certificates. If your certificate was issued before November 2021, request a new one as a precaution.
Can malware installed via GoDaddy affect my visitors?
Yes. Malware on a compromised site can redirect visitors to phishing pages, steal form data, or push malicious code to users' browsers. This is why regular file scanning and change monitoring are essential practices, not optional extras.
Is migrating away from GoDaddy complicated?
For most WordPress sites, a migration takes between one and four hours with the right tools (Duplicator, All-in-One WP Migration). The main care is managing DNS propagation to minimize downtime, which is typically under 30 minutes when planned properly.
Useful resources
Other providers and guides worth comparing: