In a joint statement, it is mentioned that: “an unauthorized third party gained access to a limited number of systems on all three sites during the last days of August 2019. As a result, information from these accounts may have been compromised.”
According to network security experts, the threat actors obtained multiple details about users, including:
Full names
Addresses of hosted websites
Email addresses
Phone numbers
Services contracted on each hosting site
As a protective measure, Web.com will require all its users to reset their passwords; however, a company representative mentioned that password encryption is a standard practice on this platform, so user access keys remained protected during the incident: “We do not believe that information was exposed as a specific result of this incident,” the spokesperson added.
Likewise, it was specified that users’ payment card data was not exposed during this incident, as this information is handled by a certified third party. The company states that the data breach has already been reported to the relevant authorities. However, the company mentions that users should not let their guard down and remain alert for any suspicious activity in their bank accounts, especially online.
Finally, network security specialists from the International Institute of Cyber Security (IICS) mention that the danger remains latent, as the threat actors responsible for this attack could use the compromised information to deploy spear phishing campaigns.
Additionally, they recommend that users of any of these web hosting services not wait for instructions from the companies and reset their access credentials as soon as possible. Given the potential start of a sophisticated phishing campaign, users are also advised to ignore suspicious-looking emails, as well as any attachments or links to external sites they may receive.



