Hackers hijack Google domains after breaching ccTLD registries
Attackers breached .gh, .sl, and .as operators, hijacked DNS, and obtained TLS certificates for Google and others.
Attackers breached third-party operators of the Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) ccTLD registries and changed authoritative DNS records. That control let them obtain valid HTTPS certificates and point affected domains, including several Google domains and other major brands, at attacker infrastructure. Google said its own systems were not compromised and that the issuing certificate authorities did not act improperly. Chrome blocked the unauthorized certificates through CRLSets, but Google warned the lists may be incomplete and do not protect non-Chrome users.