Reinsurance News

Cybercube warns underwriters after GoDaddy attack

26th November 2021 - Author: Katie Baker

New research has highlighted how a Single Point of Failure (SPoF) cyber attack represents one of the most likely ways the world could experience its first systemic cyber event, according to analytics company, CyberCube.

cybercube-logoThe GoDaddy breach is the latest in a series of cyber attacks on SPoFs including the SolarWinds attack of 2020 and, more recently, an attack on Microsoft Exchange servers.

The potential for one of these attacks to have systemic consequences triggering catastrophic losses for cyber insurers is increasing.

GoDaddy took action and forced the threat actor out of the company’s network, but not before 1.2 million GoDaddy customers’ login credentials were stolen, putting those accounts at high risk of being targeted in business email scams and phishing campaigns.

CyberCube has warned re/insurers that the breach should prompt a review of their understanding of their SPoF exposures, especially organisations like GoDaddy that are considered to be part of the “backbone of the global public internet.

William Altman, Cyber Security Consultant with CyberCube, said: “This event is yet another wake-up call to re/insurers that large-scale cyber loss events that impact tens of thousands of companies and millions of users at the same time are increasingly possible.

“Data breaches at internet-enabling SPoFs such as web-hosting providers, email services providers, certificate authorities, and domain registrars like GoDaddy can lead to the mass theft of login credentials and email addresses.

“This in turn puts the subjects of the stolen data at greater risk of being targeted in other attacks. In the worst-case scenario, threat actors could target all of the stolen email addresses obtained from GoDaddy with targeted malware-laden phishing emails.”

Darren Thomson, Head of Cyber Security Strategy for CyberCube added: “Cyber underwriters should look to GoDaddy as a warning for the types of high-risk cyber security signals to look out for when deciding on whether or not to underwrite an account.

“CyberCube’s single risk cyber underwriting solution, Account Manager, flagged a high risk of ‘Exposed Credentials’ for GoDaddy prior to this latest breach.

“GoDaddy was observed as having over 270 different exposed records in the last 60 days including email addresses, combinations of passwords and emails that can be used to login to the company’s network.”

Print Friendly, PDF & Email

Recent Reinsurance News

Getting your daily reinsurance news from Reinsurance News is a simple way to receive only the reinsurance industry news that matters, delivered directly to your email inbox.

  • Only email is mandatory, but the more you tell us about yourself the better we can serve you in future!
  • This field is for validation purposes and should be left unchanged.

By submitting the form you are giving your consent to be emailed by us.

Read previous post:
16% of US hurricanes now hitting northern states: Chaucer

New research from specialty re/insurance group Chaucer shows that 16% of US hurricanes and storms are now hitting northern states...