Three ccTLD Registry Hijacks Yield Unauthorized Google Certificates
Attackers hijacked the .gh, .sl, and .as registries, changed DNS, and obtained unauthorized HTTPS certificates for Google and others; Google was not breached and the certificates were revoked.
Google disclosed on October 6, 2026, that attackers compromised third-party operators of the Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) country-code registries and changed authoritative DNS records. That access let them pass domain-control validation and obtain unauthorized HTTPS certificates for Google domains and for other organizations, without breaching Google’s own systems. The Hacker News reported that Certificate Transparency logs show 12 domain-validated certificates for Google and YouTube names—11 from Let’s Encrypt and one from ZeroSSL—logged between September 22 and 27 for names including google.com.gh, google.sl, and google.as; other outlets did not cite that count and described additional unnamed brands. Google said the issuing certificate authorities did not act improperly, Chrome blocked identified certificates via CRLSets, and the CAs revoked them. Sources differ on misuse: Google did not confirm the certificates were used to intercept traffic and did not name the attackers, while BleepingComputer said affected domains were pointed at attacker infrastructure. Google warned the review may be incomplete and that Chrome blocks do not reliably cover non-Chrome users, and urged owners to monitor Certificate Transparency logs and set restrictive CAA records, noting CAA cannot stop issuance during an active DNS hijack.
- On October 6, 2026, Google (its Chrome Secure Web and Networking team) said attackers compromised third-party operators of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code registries.
- Attackers changed authoritative DNS records, passed domain-control validation, and obtained unauthorized HTTPS certificates for Google domains and other organizations.
- The Hacker News, citing Certificate Transparency logs, reported 12 domain-validated certificates for Google and YouTube names—11 from Let's Encrypt and one from ZeroSSL—logged September 22–27, including google.com.gh, google.sl, and…
- Google said its own systems were not compromised and that the issuing certificate authorities did not act improperly.
- Chrome blocked identified certificates through CRLSets, and the issuing CAs revoked them; The Hacker News said all 12 Google and YouTube certificates were revoked.
- Google did not confirm the certificates were used to intercept traffic and did not name the attackers; BleepingComputer said the DNS control was used to point affected domains at attacker infrastructure.
- Google warned its review may have missed domains and that Chrome CRLSet blocks do not reliably protect non-Chrome users.
- Reports say CAA records, including ACME account bindings, cannot stop issuance during an active DNS hijack but can limit reuse of cached validation; Google urged owners to monitor CT logs and publish restrictive CAA records.
Coverage timelineoldest first · each row is one article
- · 3d agoHackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Help Net Security· 82
Attackers hijacked Ghana, Sierra Leone, and American Samoa domain registries and obtained HTTPS certificates for Google domains.
- · 3d agoHackers Hijack .gh, .sl and .as Registry to Obtain Unauthorized HTTPS Certificates
Cyber Security News· 76
Attackers hijacked .gh, .sl, and .as registries to obtain unauthorized TLS certificates for Google and others.
- · 3d ago