GoDaddy is investigating allegations that it transferred control of a 27-year-old domain belonging to a U.S. nonprofit to another customer without enforcing the account’s configured authentication controls or obtaining valid supporting documentation. According to Flagstream Technologies partner Lee Landis and a separate writeup cited in reporting, the transfer was approved within four minutes on April 18 through an account recovery process and was attributed in the audit trail to an internal user. The nonprofit, which reportedly operates 20 locations, lost access to its website and email for four days after the domain disappeared from its GoDaddy account without notice.
Flagstream said GoDaddy staff may have confused the nonprofit’s primary domain with another domain that a woman identified as Susan was legitimately trying to recover, while both Flagstream and the unintended recipient disputed GoDaddy’s claim that proper documentation and authorization had been provided. The domain was restored only after the recipient realized she had received the wrong asset and cooperated directly to transfer it back, while GoDaddy support allegedly failed to resolve the issue despite repeated outreach. The incident has raised concerns over account recovery abuse, phishing, business email compromise, and the broader risk created when control of a domain’s web and email infrastructure is mistakenly reassigned.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
After the incident became public, GoDaddy said it was investigating the allegations, maintained that standard procedures had been followed with proper documentation and authorization, and said it was reinforcing processes to catch customer-representative miscommunications earlier.
The issue was resolved when the unintended recipient realized she had received the wrong domain and cooperated directly with Flagstream to transfer it back to the nonprofit. Reports said GoDaddy support had not resolved the problem despite repeated calls and emails before the recipient's intervention.
Following the erroneous transfer, the affected U.S. nonprofit reportedly lost control of its domain, causing about four days of website and email downtime across its operations. The incident raised concerns about potential phishing, business email compromise, and broader identity infrastructure abuse while the domain was under чужой control.
On April 18, GoDaddy allegedly approved an account recovery request within four minutes and transferred control of a 27-year-old nonprofit domain to another customer. Flagstream Technologies said the audit trail showed the action was initiated by an internal GoDaddy user without the account's configured authentication controls or valid supporting documentation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.