Hackers hijack Google domains after breaching ccTLD registries
Attackers breached .gh, .sl, and .as operators, hijacked DNS, and obtained TLS certificates for Google and others.
Attackers breached third-party operators of the Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) ccTLD registries and changed authoritative DNS records. That control let them obtain valid HTTPS certificates and point affected domains, including several Google domains and other major brands, at attacker infrastructure. Google said its own systems were not compromised and that the issuing certificate authorities did not act improperly. Chrome blocked the unauthorized certificates through CRLSets, but Google warned the lists may be incomplete and do not protect non-Chrome users.
- Attackers compromised operators of the .gh, .sl, and .as registries.
- DNS changes let them obtain valid TLS certificates and impersonate brands.
- Google says its systems were not compromised and the CAs acted properly.
- Chrome blocked the certificates with CRLSets; other browsers may stay exposed.
- CAA records do not stop issuance during an active DNS hijack.
Full article535 words · extracted from bleepingcomputer.com · click to collapse

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.
Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but "did not involve a compromise of Google’s systems."
By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don't own.
CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.
Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.
This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.
Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.
The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.
After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.
“Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained.
“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”
CRLSets is a Chrome “emergency mechanism” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.
However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.
The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.
“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.
Google urges domain owners to:
- Monitor CT logs across their entire domain portfolio, including parked domains.
- Publish restrictive Certification Authority Authorization (CAA) records as needed to limit issuance to authorized ACME accounts and validation methods.
Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.
The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.