GoDaddy, the U.S.-based publicly traded internet domain registrar and web hosting company, reported that in October 2019, it experienced data breach.
The world’s largest domain name registrar said that an "unauthorized individual" managed to gain access to SSH accounts used in its hosting environment.
As a result, attackers may have obtained GoDaddy customers' web hosting account credentials.
To prevent any further damage, GoDaddy said that it needed to reset all user passwords. And as compensation to affected customers, the company said that it would provide them with a year of its website security and malware removal service for free.
"These services run scans on your website to identify and alert you of any potential security vulnerabilities," it said. "With this service, if a problem arises, there is a special way to contact our security team and they will be there to help."
The data-breach notice was filed with the California Attorney General.

SSH is also called 'Secure Shell'.
It's a cryptographic network protocol for operating network services securely over an unsecured network. It is typically used to log into a remote machine and execute commands, but can also be used to transfer files using the associated SSH file transfer (SFTP) or secure copy (SCP) protocols.
With the data leaked. there is no saying what attackers can do to users' accounts.
“The investigation found that an unauthorized individual had access to your login information used to connect to SSH on your hosting account. We have no evidence that any files were added or modified on your account. The unauthorized individual has been blocked from our systems, and we continue to investigate potential impact across our environment.”
GoDaddy said that it has launched an investigation “immediately” upon discovering the breach, but didn’t say how the attack was carried out.
According to a spokesperson from GoDaddy:
"This affected approximately 28,000 customers. We immediately reset these usernames and passwords, removed an authorized SSH file from our platform, and have no indication the individual used our customers’ credentials or modified any customer hosting accounts. The individual did not have access to customers’ main GoDaddy accounts.”
Fortunately for GoDaddy and users, the security breach didn't impact the "main GoDaddy.com customer account", meaning that any information within it wasn't accessed.
From more than 19 million customers worldwide, only 28,000 accounts were affected by the attack.
GoDaddy that was founded by war-veteran Bob Parsons in 1997, didn't confirm how long the attacker had access to the credentials.























































































































































































































































































































































































