• News/
  • https://www.bleepingcomputer.com/news/security/ftc-orders-godaddy-to-fix-poor-web-hosting-security-practices/

FTC orders GoDaddy to fix poor web hosting security practices

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 16, 2025
·
Updated

The Federal Trade Commission (FTC) will require web hosting giant GoDaddy to implement basic security protections, including HTTPS APIs and mandatory multi-factor authentication, to settle charges that it failed to secure its hosting services against attacks since 2018. FTC says the Arizona-based company's claims of reasonable security practices also misled millions of web-hosting customers because GoDaddy was instead "blind to vulnerabilities and threats in its hosting environment" due to its failings to implement standard security tools and practices. "Millions of companies, particularly small businesses, rely on web hosting providers like GoDaddy to secure the websites that they and their customers rely on," said Samuel Levine, Director of the FTC's Bureau of Consumer Protection. "The FTC is acting today to ensure that companies like GoDaddy bolster their security systems to protect consumers around the globe." According to the FTC's complaint, GoDaddy's unreasonable security practices included failing to use multi-factor authentication (MFA), manage software updates, log security-related events, segment its network, monitor for security threats (including by failing to use software that could actively detect threats from its many logs), and use file integrity monitoring. The company also failed to inventory and manage assets, assess risks to its website hosting services, and secure connections to services that provide access to consumer data. The FTC says that, between 2...

Read full article

Affected Software

3 affected components
GoDaddy Managed WordPress
GoDaddy cPanel shared hosting
GoDaddy web hosting
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security measures has the FTC ordered GoDaddy to implement?

The FTC has ordered GoDaddy to implement HTTPS APIs and mandatory multi-factor authentication.

2

What prompted the FTC's intervention with GoDaddy?

The FTC intervened due to charges that GoDaddy failed to secure its web hosting services adequately.

3

Which GoDaddy products are affected by the FTC's order?

The affected GoDaddy products include Managed WordPress, cPanel shared hosting, and general web hosting services.

4

What are the potential risks of inadequate web hosting security?

Inadequate web hosting security can lead to data breaches, unauthorized access, and service disruptions.

5

What is the significance of this FTC ruling for web hosting services?

This ruling emphasizes the importance of basic security protocols in protecting user data for web hosting providers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203