Stolen Domains Not The Only GoDaddy Phishing Threat

I’ve written a number of articles about phishing attempts made to induce GoDaddy customers into giving up their login credentials. I think phishing is one of the leading causes of domain name theft, and it appears  to have reached a crescendo in the last year. It seems that domain theft isn’t the only objective of phishing attackers.

Jeremy Kirk published an article on  CIO.com warning that attackers are using hijacked domain registrar accounts to  infect computers with malware.  “Hundreds of hacked domain name accounts registered through GoDaddy are being used as part of a highly effective campaign using the Angler exploit kit to infect computers with malware,” wrote Kirk. The article cited a blog post written by Nick Biasini, an outreach engineer with Cisco Systems.

Kirk went on to explain what is happening with the subdomains:

An Angler attack starts when someone views a malicious advertisement. That advertisement then redirects the person to one of the hacked subdomains, which either delivers the exploit kit or redirects to another website hosting the kit.

Based on my understanding of this, it does not seem like the issue is uniquely associated with GoDaddy. My understanding is that because GoDaddy has the largest customer base, phishing attacks typically target  GoDaddy customers more regularly. If the recipient is not  able to distinguish a phishing email from a legitimate communication, they may give up their information unknowingly.

It’s important that GoDaddy customers and customers of other domain registrars use two factor authentication or other security measures offered by the registrar. Based on this article, it is clear that domain name theft is not the only issue one needs to be concerned about related to phishing.

If you receive an email you believe is a phishing attempt, you should consider reporting it to GoDaddy. This can help the company thwart the attack and save others from falling prey to it.

Elliot Silver
Elliot Silver
About The Author: Elliot Silver is an Internet entrepreneur and publisher of DomainInvesting.com. Elliot is also the founder and President of Top Notch Domains, LLC, a company that has closed eight figures in deals. Please read the DomainInvesting.com Terms of Use page for additional information about the publisher, website comment policy, disclosures, and conflicts of interest. Reach out to Elliot: Twitter | Facebook | LinkedIn
  1. That the more reasons why I chose GoDaddy , they have the 2 authentication methods.
    NameCheap.com uses the authentication too—good for them

    We should give a shout out to those registrars that use the 2 authentication methods -I only do business with them.

    What good about Godaddy is that when you talked to their support, they will send you the code on the phone to make sure you are the rightful owner. They even ask you for your personal code.

    GoDaddy -Excellent customer service!!

  2. I dislike Godaddy’s system for the following reasons:

    1. The two factor doesn’t memorize your desktop or mobile device. Instead, you must enter the text message code every time you login. And Godaddy logs you out automatically pretty fast. And text messages sometimes arrive late. So just like the Godaddy interface, the Godaddy authentication is highly annoying.

    2. If your account is somehow compromised, almost EVERY hack report begins the same way: “I saw an email from Godaddy saying my domain was being transferred and that I had until [6 days from today] to stop it, but when I logged in, the *domains were already gone*.” Godaddy lets you immediately release the domains for transfer, which is great when YOU want to transfer them out, but bad when your account has been compromised as there is not enough time for you to react. Their release feature releases it that second.

    3. For the love of God, in your security settings, turn off the last 4 digits of your credit card validation. Otherwise, hackers can use that in lieu of the 2 factor authentication.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Recent Posts

Do You Own Your FirstNameLastName.com?

10
Owning your first name last name .com domain name is a flex for some people. It can make it easier for people to find...

Moonshot BIN Pricing, but Invite a Negotiation

0
TonyNames shared another exceptional .ai domain name sale earlier today. Tony sold the 3 letter FRL.ai domain name for $30,000. In the post announcing...

The $5k Limit

8
I have been in a negotiation with a buyer, and it seems like we are close to an agreement on a domain name sale....

No Nameserver Change ≠ Fake Sale

1
A few years ago, I privately closed a very substantial domain name sale. Following the sale, the buyer did absolutely nothing with the domain...

GoDaddy to Launch “Premium Domain Marketplace” on DomainNames.com

6
The Afternic X account posted a link on X without much context that caught my attention this morning: 👀 https://t.co/JL8P45lRng 🔜 — Afternic (@afternic) October 3, 2025 https://platform.twitter.com/widgets.js Visiting...