Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • ANTITRUST NEWS: FTC and DOJ jointly issue antitrust guidelines for business activities affecting workers
    • ANTITRUST NEWS: John Deere harmed farmers with high repair costs, FTC alleges
    • ANTITRUST NEWS: Justice Department and OSHA warn against NDAs can hinder antitrust reporting
    • ANTITRUST—D. Kan.: Wealth management industry employees' class action lawsuit survives dismissal motion by parent entity
    • ANTITRUST—S.D. Iowa: Pathologists test negative on their pleading of ‘central Iowa’ antitrust claims
    • BLOG TRACKER—Noteworthy blog posts and other commentary
    • CONSUMER PROTECTION NEWS: FTC acts to make GoDaddy improve security for its website hosting services
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Antitrust Law Daily Wrap Up, CONSUMER PROTECTION NEWS: FTC acts to make GoDaddy improve security for its website hosting services, (Jan 16, 2025)

    Organizations Mentioned:Bureau of Consumer Protection | GoDaddy, Inc.

    By Peter Reap, J.D., LL.M.

    The company agreed to implement strong new measures to settle FTC charges.

    The FTC announced that it has filed an administrative complaint against website hosting company GoDaddy and at the same time entered into a proposed settlement order with the c ...

    By Peter Reap, J.D., LL.M.

    The company agreed to implement strong new measures to settle FTC charges.

    The FTC announced that it has filed an administrative complaint against website hosting company GoDaddy and at the same time entered into a proposed settlement order with the company to settle charges that the company failed to secure its website-hosting services against attacks that could harm its customers and visitors to the customers’ websites. According to the lawsuit, the lax security measures that GoDaddy has relied upon up until now have resulted in several major data breaches that put both its customers and consumers visiting the websites of those customers at risk (In the Matter of GoDaddy, Inc., FTC File No. 2023133, Jan. 15, 2025).

    GoDaddy is one of the largest website hosting companies in the world, with approximately five million customers. Since at least 2015, GoDaddy has marketed itself as a secure choice for customers to host their websites, touting its commitment to data security and careful threat monitoring practices in multiple locations, including its main website for hosting services, its “Trust Center,” and in email and online marketing.

    However, since 2018, the company has violated Section 5 of the FTC Act by failing to implement standard security tools and practices to protect the environment where it hosts customers’ websites and data, and to monitor it for security threats. Specifically, the complaint alleges that GoDaddy failed to: (a) inventory and manage assets; (b) manage software updates; (c) assess risks to its website hosting services; (d) use multi-factor authentication; (e) log security-related events; (f) monitor for security threats, including by failing to use software that could actively detect threats from its many logs, and failing to use file integrity monitoring; (g) segment its network; and (h) secure connections to services that provide access to consumer data. Further, all of these failures made GoDaddy’s representations about security false or misleading.

    GoDaddy experienced several major compromises of its hosting service between 2019 and December 2022, when malicious actors repeatedly gained access to its customers’ websites and data, causing harm to its customers and putting them and visitors to their websites at risk of further harm. GoDaddy’s customers and other consumers could not avoid this harm, and the harm was not outweighed by benefits to consumers or competition, according to the complaint.

    The complaint and FTC analysis to aid public comment detail examples of threat actors who have infiltrated its computer systems including its Shared Hosting environment and put customer and consumer data at risk. It further details examples of discoveries by the GoDaddy security team that its servers were running software with known vulnerabilities, and the threat actor had exploited these vulnerabilities to replace server files with malicious versions.

    Count 1 of the complaint charges that its failure to employ reasonable and appropriate measures to protect the Shared Hosting environment from unauthorized access has caused or is likely to cause substantial injury to consumers is an unfair act or practice. Count 2 charges that GoDaddy’s representations that it has used reasonable and appropriate measures to protect the Shared Hosting environment against unauthorized access is false or misleading. Count 3 charges GoDaddy with not adhering to the EU-U.S. and/or Swiss-U.S. Privacy Shield Principles, including the Security Principle (Principle 4). All of the above constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.

    Proposed settlement order. The FTC’s proposed order will prohibit GoDaddy from misleading its customers about its security practices in the future and ensure that it has reasonable security going forward, including:

    • Prohibit GoDaddy from making misrepresentations about its security and the extent to which it complies with any privacy or security program sponsored by a government, self-regulatory, or standard-setting organization, including the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks;

    • Require GoDaddy to establish and implement a comprehensive information-security program that protects the security, confidentiality, and integrity of its website-hosting services; and

    • Mandate that GoDaddy hire an independent third-party assessor who conducts an initial and biennial review of its information-security program.

    Levine comments. “Millions of companies, particularly small businesses, rely on web hosting providers like GoDaddy to secure the websites that they and their customers rely on,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “The FTC is acting today to ensure that companies like GoDaddy bolster their security systems to protect consumers around the globe.”

    Companies: GoDaddy, Inc.

    News: ConsumerProtection Privacy CyberPrivacyFeed DataPrivacy FederalTradeCommissionNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use