GoDaddy Gave a Domain to a Stranger Without Any Documentation

A GoDaddy customer lost a 27-year-old domain to an unauthorized transfer initiated by a GoDaddy internal user despite dual two-factor authentication and paid protection services, resulting in four days of total email and website outages across a national organization. The incident revealed critical gaps in GoDaddy's security protocols, account recovery procedures, and customer support escalation processes, with the customer making 32 calls and 9.6 hours of phone time while being redirected between generic email addresses and disconnected case numbers. This case demonstrates a significant supply chain and vendor risk for any organization relying on third-party domain registrars, highlighting the need for IT leaders to implement redundancy strategies and formal incident response protocols with their critical infrastructure providers.

Hacker News3 min read
Read full article
GoDaddy Gave a Domain to a Stranger Without Any Documentation
A GoDaddy customer lost a 27-year-old domain to an unauthorized transfer initiated by a GoDaddy internal user despite dual two-factor authentication and paid protection services, resulting in four days of total email and website outages across a national organization. The incident revealed critical gaps in GoDaddy's security protocols, account recovery procedures, and customer support escalation processes, with the customer making 32 calls and 9.6 hours of phone time while being redirected between generic email addresses and disconnected case numbers. This case demonstrates a significant supply chain and vendor risk for any organization relying on third-party domain registrars, highlighting the need for IT leaders to implement redundancy strategies and formal incident response protocols with their critical infrastructure providers.