If you've ever had an account or relationship with GoDaddy, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.

What Happened

GoDaddy disclosed in November 2021 that an unauthorized party had used a compromised password to access its Managed WordPress hosting environment for approximately two months, from September to November 2021, affecting around 1.2 million active and inactive customers.

What Data Was Exposed

The exposed data included customer email addresses and customer numbers for all affected accounts, plus the original WordPress admin password (set at account provisioning) in plaintext for a subset. sFTP and database usernames and passwords were also exposed, and for a smaller number of active customers, SSL private keys were exposed as well.

Why This Still Matters

Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

When did the GoDaddy data breach happen?

The unauthorized access occurred between approximately 6 September and 17 November 2021, and GoDaddy disclosed the breach publicly on 22 November 2021, affecting about 1.2 million Managed WordPress customers.

What data was stolen in the GoDaddy breach?

Email addresses and customer numbers were exposed for all affected accounts. The original WordPress admin password was exposed in plaintext for a subset, along with sFTP/database credentials, and SSL private keys for some active customers.

How did attackers get into GoDaddy?

GoDaddy stated the attacker used a compromised password to gain access to the Managed WordPress provisioning system, though the company did not disclose exactly how that password was obtained.

How do I check if I was affected by the GoDaddy breach?

GoDaddy notified affected Managed WordPress customers directly and reset relevant passwords. You can also check your email at Scan My Shadow.

What should GoDaddy Managed WordPress customers do?

Reset all passwords associated with your account (WordPress admin, sFTP, database), and if you had SSL certificates issued during the breach window, consider reissuing them given the exposure of private keys.

Sources

Related Reading