CSIDB logo
Incident

GoDaddy

Incident posture

Attack window
Mar 2020
Location
Malaysia
Status
Historical
CIA posture
Available to members
Updated
2026-07-16 14:22

Linked entities

Victim
GoDaddy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A spear-phishing attack compromised a customer service employee at GoDaddy, enabling unauthorized access to modify domain settings for multiple customers, including Escrow.com. The attacker altered Escrow.com's homepage to display a plain text message for approximately two hours, though the company confirmed no internal systems, customer data, funds, or domains were breached beyond the temporary website defacement. The incident highlighted risks stemming from compromised registrar employee credentials affecting third-party domain configurations.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around March 30, 2020, a spear-phishing attack compromised a customer service employee at GoDaddy, the world’s largest domain registrar. The phishing incident granted the attacker access to view and modify critical customer records within GoDaddy’s systems. This unauthorized access was exploited to alter domain settings for approximately six GoDaddy customers, including Escrow.com, a transaction brokering platform. The attacker modified Escrow.com’s domain configuration, leading to a defacement of its homepage. Starting around 5:00 p.m. Pacific Time on Monday, Escrow.com’s website displayed a plain-text crude message instead of its normal content for approximately two hours. DomainInvesting.com’s Elliot Silver observed the defacement and reported it. The incident did not involve a breach of Escrow.com’s internal systems, as confirmed by Matt Barrie, CEO of Freelancer.com, Escrow.com’s parent company.

Barrie stated that no Escrow.com customer data, funds, or domains were compromised during the incident. He indicated Escrow.com would release additional details in the following days but emphasized the integrity of their systems remained intact. KrebsOnSecurity contacted Barrie and Escrow.com for further clarification and separately reached out to SecurityTrails CEO Chris Ueland regarding the incident. The attack vector was confined to the compromise of GoDaddy’s customer service account, which enabled the attacker to manipulate domain records for targeted customers. The full scope of changes made to other affected GoDaddy customers beyond Escrow.com was not disclosed in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB