{
  "type": "bundle",
  "id": "bundle--77adc552-7784-55ea-8603-35a1fa00841b",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--8dfc61c8-6cf8-52c2-84e5-7213e11b4a0f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:52ce698a-f6dc-57e2-9787-16cbedc10f69",
      "name": "GoDaddy",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--ad7399cb-cd22-5628-8f64-df0091b609cc",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:35136025-311e-5e68-8bc7-8f90eb2249ac",
      "name": "GoDaddy multi-year compromise"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--b9519f16-86ee-57de-80fb-d1095b4ff37c",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:074d81c5-dd2b-5772-a679-3fdea56ced71",
      "name": "GoDaddy multi-year compromise"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e1762d7f-08f0-5399-874c-56b8af008ade",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:543a00fc-153b-5c0f-b74e-e9031073825a",
      "relationship_type": "affected-organization",
      "source_ref": "incident--b9519f16-86ee-57de-80fb-d1095b4ff37c",
      "target_ref": "identity--8dfc61c8-6cf8-52c2-84e5-7213e11b4a0f",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:72c9a5ca-8829-5ac7-9fcf-75f3079b2005",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--48a66021-6629-57a4-84f8-c9480f9d8c7f",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:c83660c9-3280-538d-a5d8-3b4bedfafa4c",
      "confidence": 84,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:10683292-2faa-54d6-978b-5029d07a3904",
          "description": "In each of the five years ended December 31, 2023, our customer retention rate was approximately 85%, and in 2023, our retention rate for customers who had been with us for over three years was approximately 92%.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Same threat actor over 3 years; SSH keys, source code, customer credentials."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--9382ac7a-a507-51ce-839a-abf859d96eb3",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:5f5a34d0-6473-5649-84f1-3331c3467fc7",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:3a5cb4e2-901e-5303-a0c5-4fa1e7fdd098",
          "description": "Security personnel and consultants retained by our service providers may also be involved in cases where our vendors experience a cybersecurity incident.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes a forensic or specialist investigation of the incident."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--d5c6767e-48b8-55f1-84b4-cb579f4fe8fe",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:6db7f272-a1d7-58d3-810e-dea1c55b6dec",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:778cf713-000f-5100-8b4b-d3b166c29210",
          "description": "Social engineering efforts may compromise our personnel or those of our third-party vendors, leading to unauthorized access to information systems we have a responsibility to protect, which could lead to the unauthorized acquisition of information, the unavailability of our information systems (or information contained on those systems) or the compromise of customer accounts.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--dd2612fe-6c54-59aa-8bde-c5c7e999826b",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:1240bd59-b04b-5a3a-831d-2d2147fe681e",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:5e5219cc-8f3b-5b62-a344-510f56fe459d",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the godaddy multi-year compromise involving GoDaddy."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--e25b6c6e-454f-579f-8d50-654d92c79cea",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:b48053b4-cba3-56c8-b882-666c6935f212",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1213/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--f8dc40cc-78a9-52ab-815e-7b684a818ed3",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:2d8eae5a-ded5-5773-bf6c-c4210a2217dc",
      "confidence": 85,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1609711/000160971124000022/gddy-20231231.htm",
          "external_id": "cit:7f1ffc47-23c7-5d36-8614-d7f9bb7c7276",
          "description": "In November 2021, using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress (MWP), which impacted up to 1.2 million active and inactive MWP customers across multiple GoDaddy brands.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:ff7b02813fdf52c7e7841e51dd61d5f97ee5f0e17fe3fe2258084cc4d1d4b740"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Multiple linked intrusions treated as one long-running compromise."
      }
    }
  ]
}
