Attackers hijack country-code domains to impersonate Google and other services
Attackers hijacked .gh, .sl, and .as DNS to get certificates impersonating Google and others.
Google said attackers compromised infrastructure behind the .gh, .sl, and .as country-code domains and used DNS control to pass validation and obtain trusted HTTPS certificates for Google domains and other organizations. Google's own systems were not compromised and encryption was not broken, but valid certificates plus traffic redirection could impersonate legitimate services. Google blocked unauthorized certificates in Chrome, worked with certificate authorities to revoke them, and later blocked suspicious certificates for other organizations. It warned the review may have missed domains and that Chrome interventions do not reliably protect non-Chrome users.