Darknet

Godaddy Employees Tricked into Handing Control Cryptocurrency Domains to Hackers

Employees of GoDaddy, the big daddy of domain name registrars, were target by a vishing scam late last week.

And this is exactly what happened to employees of GoDaddy. The employees were tricked into transferring ownership and/or control over targeted domains to the tricksters, reported by Krebs on Security.

This, however is not the first instance of such an activity involving GoDaddy employees. 

In March this year, the employees were tricked into allowing the attackers to take control of multiple domain names, and 28000 customers’ credentials were breached. You can read more about this here

Liquid.com’s, a cryptocurrency trading platform, CEO Mike Kayamori said in a blog post “On the 13th of November 2020, a domain hosting provider “GoDaddy” that manages one of our core domain names incorrectly transferred control of the account and domain to a malicious actor…….We believe the malicious actor was able to obtain personal information from our user database.  This may include data such as your email, name, address and encrypted password”.

Liquid.com does not seem to be the only one that has come out. Nicehash too in a blog post confirmed the breach, “In the early morning (UTC) hours of November 18, 2020, the NiceHash domain was not reachable. The domain registrar GoDaddy had technical issues and as a result of unauthorized access to the domain settings, the DNS records for the NiceHash.com domain were changed“.

Several reports state that several other cryptocurrency trading platforms such as Bibox.com, Celsius.network, and Wirex.app were also targeted by the same group. However, there is no official comment from these platforms.

Though these attacks are rampant, there are several ways to mitigate these attacks, few of which are listed below:

  1. Restrict VPN connections to only managed devices
  2. Restrict VPN access hours
  3. Improve 2FA and OTP authentication
  4. Bookmark the correct corporate VPN
  5. Verify web-links before clicking on them
  6. Do not easily trust phone calls and emails from unknown sources
  7. Evaluate your security settings

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read:

Magento Warns Users to Apply Security Updates to Fix Critical RCE, XSS & Other Vulnerabilities

Beware!! Hackers Hide Web Skimmer Stealer within EXIF Metadata to Steal Credit card Data

MageCart Hackers Steals Customer Credit Card Data from E-commerce Site Using Web Skimmer

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago