The U.S. Federal Trade Commission (FTC) has finalized an order requiring web hosting giant GoDaddy to secure its services to settle charges of data security failures that led to several data breaches since 2018. In January, the agency also alleged that GoDaddy, a major website hosting company with roughly five million customers, misled users about its security practices. The FTC found that GoDaddy was unaware of vulnerabilities in its hosting environment due to a lack of standard security measures. The FTC's order prohibits the company from misleading customers about its security protections and mandates GoDaddy to establish a robust information security program, secure APIs using HTTPS or other secure transfer protocols, and set up a software and firmware update management program. The order also requires GoDaddy to hire an independent third-party assessor to conduct biennial reviews of its information security program and report any incident where customer data was exposed, accessed, or stolen within 10 days. Among other requirements, the hosting company has to add at least one mandatory MFA for all customers, employees, and contractors' staff "to any Hosting Service supporting tool or asset, including connecting to any database" and "at least one method that does not require the customer to provide a telephone number, such as by integrating authentication applications or allowing the use of security key." According to the FTC's complaint, GoDaddy had inadequate security p...
FTC finalizes order requiring GoDaddy to secure hosting services
BleepingComputer
·Sergiu Gatlan
·Published May 22, 2025
·Updated
Affected Software
3 affected components
GoDaddy cPanel shared hosting environment
GoDaddy Managed WordPress hosting environment
GoDaddy web hosting
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the FTC finalizing an order requiring GoDaddy to improve the security of its hosting services due to past data security failures.
2
What security implications are discussed in the article?
The article highlights how GoDaddy's previous data security failures resulted in multiple data breaches affecting customer information.
3
What products are affected by the FTC's order regarding GoDaddy?
The affected products include GoDaddy's cPanel shared hosting environment, Managed WordPress hosting environment, and general web hosting services.
4
What is the reason behind the FTC's action against GoDaddy?
The FTC's action is a response to several data breaches that occurred at GoDaddy since 2018, attributed to security inadequacies.
5
What measures is GoDaddy required to take as part of the FTC's order?
GoDaddy is required to implement additional security measures to safeguard customer data and improve the overall security of their hosting services.