{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"},"incident":{"title":"Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash","date":"2020-11-13","date_precision":"day","victim_org":"GoDaddy (registrar); Liquid.com and NiceHash","sector":"Cryptocurrency","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No voice cloning was reported; the callers used conventional pretexting against registrar staff.","outcomes":["Data Breach","Credential Theft","Service Disruption"],"loss_usd":null,"loss_note":"No customer funds were reported lost. Liquid said customer funds remained secure; NiceHash said no emails, passwords or personal data were compromised.","records_affected":null,"threat_actor":"Unattributed","summary":"Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.","how_it_worked":"The attackers called GoDaddy employees and pretended to be authorised parties with a routine domain administration need, a pretext the registrar's own staff were positioned to fulfil. Once a rep made the change, the attackers held registrar-level control of the target's domain and could repoint DNS at will. For Liquid, control of the domain's MX and name server records let them take over internal email accounts, which in turn exposed customer names, addresses, encrypted passwords and identity verification documents. NiceHash saw the same DNS manipulation but reported no data compromise. The exchanges' own security was never touched; the failure was one level up, at the registrar.","lessons":"Registry lock on critical domains, which requires manual out-of-band verification before any DNS or nameserver change, defeats registrar-side social engineering outright.","confidence":"Confirmed","sources":[{"title":"GoDaddy Employees Tricked into Compromising Cryptocurrency Sites","url":"https://threatpost.com/godaddy-employees-tricked-compromise-cryptocurrency/161520/","publisher":"Threatpost"},{"title":"GoDaddy Employees Tricked Into Transferring Control of Crypto Firm Domains: Report","url":"https://www.coindesk.com/markets/2020/11/22/godaddy-employees-tricked-into-transferring-control-of-crypto-firm-domains-report","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-vishing-of-godaddy-staff-hijacked-domains-of-crypto-firms-liquid-and-nic"}}