• News/
  • https://www.bleepingcomputer.com/news/security/ftc-finalizes-order-requiring-godaddy-to-secure-hosting-services/

FTC finalizes order requiring GoDaddy to secure hosting services

BleepingComputer
·
Sergiu Gatlan
·
Published May 22, 2025
·
Updated

The U.S. Federal Trade Commission (FTC) has finalized an order requiring web hosting giant GoDaddy to secure its services to settle charges of data security failures that led to several data breaches since 2018. In January, the agency also alleged that GoDaddy, a major website hosting company with roughly five million customers, misled users about its security practices. The FTC found that GoDaddy was unaware of vulnerabilities in its hosting environment due to a lack of standard security measures. The FTC's order prohibits the company from misleading customers about its security protections and mandates GoDaddy to establish a robust information security program, secure APIs using HTTPS or other secure transfer protocols, and set up a software and firmware update management program. The order also requires GoDaddy to hire an independent third-party assessor to conduct biennial reviews of its information security program and report any incident where customer data was exposed, accessed, or stolen within 10 days. Among other requirements, the hosting company has to add at least one mandatory MFA for all customers, employees, and contractors' staff "to any Hosting Service supporting tool or asset, including connecting to any database" and "at least one method that does not require the customer to provide a telephone number, such as by integrating authentication applications or allowing the use of security key." According to the FTC's complaint, GoDaddy had inadequate security p...

Read full article

Affected Software

3 affected components
GoDaddy cPanel shared hosting environment
GoDaddy Managed WordPress hosting environment
GoDaddy web hosting
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the FTC finalizing an order requiring GoDaddy to improve the security of its hosting services due to past data security failures.

2

What security implications are discussed in the article?

The article highlights how GoDaddy's previous data security failures resulted in multiple data breaches affecting customer information.

3

What products are affected by the FTC's order regarding GoDaddy?

The affected products include GoDaddy's cPanel shared hosting environment, Managed WordPress hosting environment, and general web hosting services.

4

What is the reason behind the FTC's action against GoDaddy?

The FTC's action is a response to several data breaches that occurred at GoDaddy since 2018, attributed to security inadequacies.

5

What measures is GoDaddy required to take as part of the FTC's order?

GoDaddy is required to implement additional security measures to safeguard customer data and improve the overall security of their hosting services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203