Issue with API has been resolved.
GoDaddy’s Afternic domain aftermarket platform had a security issue with its API that has since been fixed, the company told impacted customers.
In an email to impacted customers, the company stated:
On Thursday, February 12, a security researcher contacted us about a potential issue with a Web API. We immediately opened an investigation and found a misconfigured server accessible though [sic] the API. Using this API, the security researcher crafted a specific request that returned information from other customer accounts.
Through our audits, we identified this specific API call was run against a small segment of our customers’ accounts. Unfortunately, your information may have been viewed using this call, which includes your first name, last name, email address, physical address, telephone number, and your Afternic username. At no point was your password or credit card information at risk.
As soon as we identified the issue, we removed the server from rotation, securing our API infrastructure.
Please monitor for any suspicious communications that may come from third parties through the contact details that were on your Afternic account (e.g. email/telephone number).
We are very sorry this incident happened. Protecting the privacy of our customers is our top priority and we let you down in this instance. Our team is committed to preventing these types of incidents in the future and we’ll always be forthcoming in our communications with you.
A GoDaddy spokesperson confirmed that all impacted customers have been contacted.
It’s fortunate that no passwords were accessed. With fast transfer turned on, someone could change the price of domains and purchase them at a low price to effectively steal them. It would be helpful if GoDaddy enabled two-factor authentication for Afternic to make this less likely to occur.