GoDaddy ManageWP Login Phishing Campaign | MSSP Advisory
High
DateMay 6, 2026
📋Executive Summary
Attackers are buying Google Ads that appear in search results for ManageWP login queries, redirecting users to credential harvesting pages that steal GoDaddy ManageWP login credentials. The phishing sites mimic the legitimate ManageWP login interface and capture usernames and passwords when users attempt to authenticate. This targets WordPress management platform credentials that control multiple client websites simultaneously.
⚠️Why It Matters for MSSPs
ManageWP credentials provide administrative access to entire fleets of WordPress sites, meaning a compromised MSSP account exposes every WordPress client simultaneously. Your clients searching for ManageWP login pages will see these malicious ads first in Google results, and if they get compromised, you face immediate retention conversations about why their websites got breached through a platform you recommended.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.