Unstoppable Domains

Hacked at GoDaddy! Why?

Spaceship Spaceship
Watch
Impact
70
I work overnights, so I really don't buy domains or use any such services or products anymore. Well one night at work this week, while checking my phone, I got an email which I thought was spam. It was supposedly from Godaddy saying thank you for ordering a Linux hosting package at $70 a month.. Along with registering a domain literally along the lines of A12L3K4JKD999SLD1118DKS73432DD.COM

So naturally I thought this was a spam email from some spoofers. Who orders crap like that anyway?! But for giggles, I decided to log in to my Godaddy account just to double check. Tried to log in to my account, and BOOM. Wrong password... Now that's odd, because I know exactly what my password is... Tried again. Wrong Password. Now that is concerning. I call up Godaddy immediately and they have me reset my password via email. Try to log in to my email....and wrong password. WTF. So i'm pissed and telling the Godaddy rep to hold on while I reset my email password with my phone (thank God for filling out the mobile number)..

Long story short. Those orders were made on my account... Passwords were changed. I got them back and enabled 2 step verification thankfully. While deleting these orders that this SOB made, I noticed a credit card number in my account that ISN'T mine... It was a Mastercard and I never had a Mastercard. Ever.

I thought recently that this SOB might of been using a stolen credit card in my account. How do I prevent the card owner from coming after me when he see's this charge on his credit card? Luckily I caught this just minutes after it happened thanks to my smartphone. But I'm sure Godaddy charged him/her immediately. Godaddy support told me that I had to delete the orders myself and Credit Card from perpetrator. Said he would make a note.

What else should I do to protect me? I did nothing wrong. And what was this freaking SOB doing ordering this crap in the first place?????? What was his punk *** doing with a $70 linux package and A12L3K4JKD999SLD1118DKS73432DD.COM or some bullcrap like that???


NOTE: Also I haven't heard a damn word from Godaddy since. Guess they aren't going to do jack to try and catch this guy?
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Unstoppable DomainsUnstoppable Domains
Nowadays, 2 way authentication is very important. Unfortunately Godaddy implemented only for US residents :(

many people complained about it but still they aren't try to implement all over world.

compared to other companies godaddy sessions could be easy to hack / stole by using encrypted keys.
 
1
•••
The important thing is that you contacted GoDaddy right away and had them make note of it on your account. If the card owner see's it on their bill, they will likely contact who the charge came from, GoDaddy. GoDaddy will likely look it up and see it associated to your account, along with the note from the guy you spoke to, and explain it to them. I don't think they'll come after you directly.
 
1
•••
What was wrong was either 1) You use a too easy password, or 2) use the same password on other internet accounts, 3) the email you use on your account has been hacked. I'd change that email account immediately.
 
2
•••
Nowadays, 2 way authentication is very important. Unfortunately Godaddy implemented only for US residents :(

many people complained about it but still they aren't try to implement all over world.

compared to other companies godaddy sessions could be easy to hack / stole by using encrypted keys.

I can say I have spoken to Paul Nicks and he said it is a priority to get two factor for everyone, hopefully with the IPO out of the way they get it done soon.
 
1
•••
What was wrong was either 1) You use a too easy password, or 2) use the same password on other internet accounts, 3) the email you use on your account has been hacked. I'd change that email account immediately.

Good point, not only that, change every password, because if you had stuff in your inbox, that may have been comprised too. If you log in to something, change the password.
 
1
•••
Did the OP click on a link in that E-mail message ? Then it may have been a phishing attack.
 
1
•••
Every time I have to confirm my email address at GoDaddy, I get worried it might be a phishing attack :(
 
1
•••
Guess they aren't going to do jack to try and catch this guy?
Especially if the perpetrator is outside the country, pretty much because such an effort requires much resources โ€” which law enforcement has and is more suitable for.

Hopefully, Go Daddy will see those charges are indeed fraudulent and proactively refund the actual card holder with minimal to trouble on your part after you notified the registrar.
 
1
•••
Besides the need to have strong passwords you should also install something like "LastPass" (I'm not affiliated with them in any way but I do use their software). You only need to remember your master password that way and the software will remember any password of any site you use and automatically sign you in. That way you're never typing any passwords anymore (so keyloggers of hackers are useless then).

It can even generate complex passwords for new or existing sites (and remember those passwords for you) so you'll never have to type (or remember) a new password anymore as well.
 
Last edited:
1
•••
Thanks guys for the help. No I don't think I ever clicked on any Godaddy emails with links... Might of been my email that the hacker got into my Godaddy account from. I changed the password immediately and used two step authentication. I better check everything that uses my email! :(

I guess Godaddy has done everything they can. I just hate hackers so much.
 
0
•••
Dynadot โ€” .com Registration $8.99Dynadot โ€” .com Registration $8.99
Domain Recover
DomainEasy โ€” Zero Commission
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back