Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
GoDaddy

GoDaddy Vendor Cyber Rating & Cyber Score

godaddy.com

At GoDaddy, you’re the star when it comes to your craft—you’re the real deal. But being an entrepreneur means juggling it all: online marketing, digital ads, website building—pretty much everything! That’s why we created GoDaddy Airo for small business owners—designed to help you conquer it all while growing your online business at AI speed. Business dreamers can go from “no clue” to “wow, I did it!” in minutes with Airo—the intelligent experience that can whip up social posts, a classy logo, or a full-blown website out of thin air—powered by AI. 20+ million customers around the globe are convincing the world (and themselves) that they’re top dog entrepreneurs with GoDaddy, and they’re crushing it. With GoDaddy Airo and your vision –


GoDaddy A.I CyberSecurity Scoring

GoDaddy
Company Information
Website:http://www.godaddy.com
Employees number:8,889
Number of followers:163,663
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:godaddy.com
GoDaddy Risk Score (AI oriented)
Between 650 and 699
logo
GoDaddyTechnology, Information and Internet
Updated:
15/05/2026
686/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
GoDaddy Global Score (TPRM)
xxxx
logo
GoDaddyTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GoDaddy
GoDaddyWeak
Current Score
686B (WEAK)
01000
8 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
685Before Incident
MAY 2026
703Before Incident
Cyber Attack
06 May 2026GoDaddy
GoDaddy and ManageWP Users: Hackers Exploit Google Ads to Steal GoDaddy ManageWP Logins

Hackers Exploit Google Ads in AiTM Phishing Attack Targeting GoDaddy ManageWP Users

686After Incident
CRITICAL-17
GODMAN1778142354
Hackers Exploit Google Ads in AiTM Phishing Attack Targeting GoDaddy ManageWP Users Cybercriminals are leveraging Google Ads to steal credentials for GoDaddy’s ManageWP, a widely used WordPress management platform, through an adversary-in-the-middle (AiTM) phishing campaign. Researchers at Guardio Labs uncovered the operation, which tricks users searching for "ManageWP" by placing a malicious sponsored ad above the legitimate result. When victims click the fake ad, they are redirected to a cloned ManageWP login page that closely mimics the real interface. Unlike traditional phishing, this attack employs a live proxy that relays credentials in real time to the authentic ManageWP service, logging the attacker in simultaneously. Stolen credentials are also forwarded to a Telegram channel controlled by the threat actors. The scheme bypasses two-factor authentication (2FA) by presenting a fake 2FA prompt, allowing attackers to intercept one-time codes and gain full access to compromised accounts. Once inside, they can control connected WordPress sites, deploy malicious plugins, exfiltrate data, or escalate access to hosting environments. Guardio Labs infiltrated the attackers’ infrastructure, discovering a custom operator-driven panel that dynamically manages phishing sessions. The framework appears to be a private tool, not a commercial phishing-as-a-service kit, with code artifacts suggesting Russian origins including a disclaimer prohibiting use against Russian targets. The campaign has already claimed at least 200 victims, though the true number may be higher given ManageWP’s 1 million+ installations. The attack underscores the growing threat of malvertising, where cybercriminals exploit paid search slots to distribute phishing and malware at scale. Users are advised to avoid searching for login pages and instead bookmark official URLs to mitigate risk.
INCIDENT DETAILS -
TYPE
Phishing (AiTM - Adversary-in-the-Middle)
MOTIVATION
Credential theft, unauthorized access to WordPress sites, data exfiltration, potential financial gain
IMPACT
Data Compromised: ManageWP credentials, WordPress site access, potentially sensitive data from connected sitesSystems Affected: ManageWP accounts, connected WordPress sitesOperational Impact: Unauthorized control of WordPress sites, potential deployment of malicious plugins, data exfiltrationBrand Reputation Impact: Potential reputational damage to GoDaddy/ManageWP due to phishing campaignIdentity Theft Risk: High (stolen credentials and 2FA codes)
DATA BREACH
Type Of Data Compromised: Credentials, 2FA codes, WordPress site accessNumber Of Records Exposed: At least 200 accounts (potentially more)Sensitivity Of Data: High (credentials and 2FA codes allow full account takeover)Data Exfiltration: Yes (credentials forwarded to Telegram channel)
APRIL 2026
703Before Incident
MARCH 2026
699Before Incident
FEBRUARY 2026
698Before Incident
JANUARY 2026
712Before Incident
Cyber Attack
01 Jan 2026GoDaddy
GoDaddy: CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

CalPhishing Attack: Cybercriminals Exploit Calendar Invites to Hijack Accounts

695After Incident
HIGH-17
GOD1778848590
Cybercriminals Exploit Calendar Invites in New "CalPhishing" Attack, Bypassing Security Controls A newly uncovered cyberattack campaign, dubbed CalPhishing, is leveraging calendar invites to hijack user accounts, according to a report by Fortra Intelligence and Research Experts (FIRE). Active since early 2026, the attack exploits iCalendar (.ics) files to bypass traditional security measures, embedding malicious meetings directly into victims’ schedules without requiring them to open the original email. ### How the Attack Works The campaign begins with an email disguised as an urgent administrative alert common subject lines include "Domain Renewal Failed" or "Reminder for Signature – Vendor Information Verification." Once processed by Outlook, the .ics file automatically adds a "tentative" meeting to the victim’s calendar, triggering official notifications and reminders. Hackers manipulate key fields within the invite: - Summary: Creates false urgency. - Location: References an "attached file" to appear legitimate. - Description: Contains phishing instructions. When opened, the meeting displays an HTML file mimicking an admin portal. Clicking it initiates a series of redirects through Cloudflare to evade security scans. ### Two Primary Lures Researchers identified two main deception tactics: 1. Fake Microsoft 365 Domain Renewal Alerts – Directs victims to a spoofed GoDaddy page. 2. Fake DocuSign Signature Requests – Tricks users into "signing" an invoice via a fraudulent portal. The attack employs ConsentFix (also known as device code phishing), a technique that steals session tokens rather than passwords. This allows hackers to bypass multi-factor authentication (MFA) by using the EvilTokens phishing kit, sold on Telegram, to automate the process. Once compromised, attackers can exfiltrate data, disrupt systems, or maintain persistent access. ### Persistence and AI-Driven Automation A key concern is the attack’s longevity standard security tools often overlook .ics files due to their trusted nature. Even if the original email is deleted or marked as junk, the meeting remains on the calendar unless manually hard-deleted. FIRE researchers warn that threat actors are likely using AI to scale these attacks, ensuring victims remain exposed long after the initial compromise. The report highlights the growing sophistication of phishing tactics, where seemingly benign calendar invites become a vector for account takeover and data breaches.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Account takeover, Data exfiltration, Persistent access
IMPACT
Data Compromised: Session tokens, User credentials, Potentially sensitive business dataSystems Affected: Microsoft 365 accounts, Email systems, Calendar applicationsOperational Impact: Potential disruption of business operations, Unauthorized access to systemsBrand Reputation Impact: Potential damage to brand reputation due to phishing attacksIdentity Theft Risk: High (session tokens and credentials compromised)
DATA BREACH
Type Of Data Compromised: Session tokens, User credentialsSensitivity Of Data: High (session tokens can bypass MFA)Data Exfiltration: Possible (attackers maintain persistent access)
DECEMBER 2025
715Before Incident
NOVEMBER 2025
715Before Incident
OCTOBER 2025
713Before Incident
SEPTEMBER 2025
711Before Incident
AUGUST 2025
710Before Incident
JULY 2025
708Before Incident
JUNE 2025
709Before Incident
Vulnerability
05 Jun 2025GoDaddy
GoDaddy

Exploitation of CVE-2025-49113 in Roundcube Webmail

715After Incident
CRITICAL-6
GOD616060625
Hackers are exploiting a critical vulnerability in the Roundcube webmail application, which is widely used by hosting providers like GoDaddy. The vulnerability, CVE-2025-49113, allows remote code execution and has a severity score of 9.9 out of 10. This vulnerability has been present for over a decade and impacts versions 1.1.0 through 1.6.10. Despite a patch being released, attackers have reverse-engineered the fix and are selling exploits on hacker forums. The wide use of Roundcube, including by government and academic institutions, makes the attack surface significant. The vulnerability can lead to data breaches and significant impact on organizations using the application.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
MOTIVATION
Financial gain through selling exploits
IMPACT
Roundcube webmail versions 1.1.0 through 1.6.10
FEBRUARY 2023
711Before Incident
Breach
01 Feb 2023GoDaddy
GoDaddy

GoDaddy Malware and Source Code Theft

665After Incident
MEDIUM-46
GOD195781023
GoDaddy, a provider of web hosting services, reported that malware and source code had been stolen from its servers. Threat actors have infiltrated the organization's cPanel shared hosting environment. Although the company is unable to pinpoint the exact moment of the initial penetration, it is currently looking into the breach to ascertain the incident's underlying cause. Random client websites might occasionally be redirected to dangerous websites by the malware that had been installed on the company's computer systems. The organization claimed that the attacks haven't affected their operations or business, but that it believes it was the target of a sophisticated threat actor's strike.
INCIDENT DETAILS -
TYPE
Malware and Source Code Theft
IMPACT
MalwareSource CodecPanel shared hosting environment
DATA BREACH
MalwareSource Code
SEPTEMBER 2021
713Before Incident
Breach
06 Sep 2021GoDaddy
GoDaddy

GoDaddy Data Breach

665After Incident
CRITICAL-48
GOD348072625
The California Attorney General reported a data breach involving GoDaddy on November 17, 2021. The breach occurred on or about September 6, 2021, when an unauthorized third party accessed customer authentication information, including customer numbers, email addresses, and login credentials. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer NumbersEmail AddressesLogin Credentials
DATA BREACH
Customer NumbersEmail AddressesLogin Credentials
NOVEMBER 2020
758Before Incident
Breach
01 Nov 2020GoDaddy
GoDaddy

GoDaddy Web Hosting Accounts Compromised

696After Incident
HIGH-62
GOD2315623
GoDaddy reported the compromising of 28,000 of its customers' web hosting accounts. One of its primary domain names is hosted by "GoDaddy," who inadvertently gave a malicious actor control of the account and site. As a result, the actor was able to manipulate several internal email accounts by altering DNS data. After some time had passed, the hostile actor was able to access document storage and compromise some of their infrastructure. Unauthorized changes were made to certain of the domain registration records' settings at GoDaddy, temporarily rerouting the site's email and web traffic. Although it appears that no emails, passwords, or other sensitive information was obtained, the business advised changing the password and turning on 2FA security.
INCIDENT DETAILS -
TYPE
Unauthorized Access, DNS Manipulation
IMPACT
Data Compromised: Document Storage, DNS DataSystems Affected: Web Hosting Accounts, Internal Email Accounts, Domain Registration RecordsOperational Impact: Temporary rerouting of email and web traffic
DATA BREACH
Type Of Data Compromised: Document Storage, DNS Data
OCTOBER 2019
806Before Incident
Breach
16 Oct 2019GoDaddy
GoDaddy.com LLC

GoDaddy Data Breach

748After Incident
LOW-58
GOD123072625
The California Office of the Attorney General reported on May 17, 2023, that GoDaddy.com LLC experienced a data breach that occurred on October 16, 2019. The breach involved unauthorized remote access to a virtual private server (VPS) due to malware that captured Secure Shell (SSH) passwords.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
VPS
JULY 2018
800Before Incident
Cyber Attack
19 Jul 2018GoDaddy
Namecheap, UnifiedLayer, IONOS and GoDaddy: New SystemBC Botnet Discovered Hijacking 10,000 Devices For DDoS Attacks

SystemBC Botnet Resurfaces with 10,000+ Infected IPs, Targeting Hosting Providers and Government Infrastructure

772After Incident
CRITICAL-28
UNINAMIONGOD1770273279
SystemBC Botnet Resurfaces with 10,000+ Infected IPs, Targeting Hosting Providers and Government Infrastructure Researchers at Silent Push have uncovered a resurgent SystemBC botnet, now controlling over 10,340 unique infected IP addresses worldwide. The malware, first identified in 2019 as "Coroxy" or "DroxiDat," converts compromised systems into SOCKS5 proxies, enabling attackers to launch DDoS attacks and obscure malicious operations. ### Scope and Persistence The botnet maintains an average of 2,888 daily active infections, with some systems remaining compromised for over 100 days. Unlike typical consumer-focused malware, SystemBC disproportionately targets hosting providers, with top affected networks including Network Solutions, UnifiedLayer, Namecheap, GoDaddy, and IONOS. This concentration in data centers ensures high-bandwidth, persistent access for cybercriminals. ### Global Distribution and High-Value Targets The U.S. leads in infections (4,300+ IPs), followed by Germany (829), France (448), Singapore (419), and India (294). Notably, compromised IPs have been linked to government infrastructure, including: - Vietnam’s Phutho provincial government (`duchop[.]gov[.]vn` on `103.28.36[.]105`) - Burkina Faso domains (`196.13.207[.]92`) Many infected systems also scanned WordPress sites for vulnerabilities, suggesting ties to broader exploitation campaigns, including ransomware deployment. ### Evasion and Command Infrastructure SystemBC’s command-and-control (C2) servers rely on bulletproof hosting providers like `bthoster[.]com` and AS213790 (BTCloud) to resist takedowns. The malware uses RC4-encrypted custom protocols in a backconnect setup, functioning as both a backdoor and ransomware loader. A newly discovered Perl-based Linux variant evaded detection by all 62 VirusTotal scanners, while droppers like SafeObject (SHA256: `0f5c81eaf357...`) unpack to deploy 264 payloads, with Russian-language artifacts hinting at its origins. The botnet’s developer, "psevdo," continues to post updates on the underground forum forum[.]exploit[.]in, despite Europol’s 2024 Operation Endgame targeting similar threats. ### Key Indicators of Compromise (IOCs) - Perl variant SHA256: `c729bf6ea292116b3477da4843aaeec73370e2bd46e7a27674671e9a65fb473a` - C2 IPs: `36.255.98[.]159` (and others) The botnet’s resilience underscores its role in DDoS operations and stealthy cyberattacks, with hosting providers and government entities remaining prime targets.
INCIDENT DETAILS -
TYPE
BotnetDDoSMalware
MOTIVATION
CybercrimeDDoS attacksRansomware deployment
IMPACT
Systems Affected: 10,340+ unique infected IPsDDoS attacksStealthy cyberattacks
DATA BREACH
Data Encryption: RC4-encrypted custom protocols

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GoDaddy ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in November 2025 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in October 2025 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in September 2025 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in August 2025 ?
?
What was GoDaddy's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on GoDaddy's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GoDaddy ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GoDaddy's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?