Hijacked .gh, .sl, and .as registries yielded unauthorized Google certificates
Attackers hijacked the .gh, .sl, and .as registries, obtained later-revoked TLS certificates for Google and others, and Chrome blocked known certificates via CRLSets.
On October 6, 2026, Google said attackers compromised the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code registries—Help Net Security and BleepingComputer called them third-party operators, GBHackers said authoritative DNS was compromised, and Malwarebytes said infrastructure behind the domains was hit—and changed authoritative DNS, including IP addresses for selected sites according to Ars Technica. That control let them pass certificate authorities' domain-control validation and obtain unauthorized HTTPS certificates for Google and YouTube names and other organizations; The Hacker News, citing Certificate Transparency logs, reported 12 domain-validated certificates (11 from Let's Encrypt and one from ZeroSSL) logged between September 22 and 27 for names including google.com.gh, google.sl, and google.as, while Infosecurity Magazine said later CT evidence showed additional affected brands. Google said its systems were not compromised and the issuing CAs did not act improperly, and Malwarebytes said encryption was not broken; Chrome blocked identified certificates with CRLSets, The Hacker News said the CAs revoked all 12, and Malwarebytes said Google later blocked suspicious certificates for other organizations, but Google warned coverage may be incomplete and does not reliably protect non-Chrome users. BleepingComputer said affected domains were pointed at attacker infrastructure, while Ars Technica said the domain owners' and DNS operators' own infrastructure was not compromised; The Hacker News and GBHackers said Google did not confirm the certificates were used to intercept traffic and did not name the attackers, and only Ars compared the case to the 2011 DigiNotar breach against roughly 300,000 users in Iran, with no victim count given for this incident. Google advised monitoring CT logs and publishing restrictive CAA records, including ACME account bindings; The Register framed CAA as limiting issuance after DNS control is restored, while BleepingComputer, GBHackers, and Infosecurity Magazine said CAA cannot stop issuance during an active DNS hijack.
- On October 6, 2026, Google said attackers compromised the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLD registries—described by some outlets as third-party operators or as infrastructure behind those domains—and changed…
- The Hacker News, citing Certificate Transparency logs, reported 12 domain-validated certificates (11 from Let's Encrypt and one from ZeroSSL), logged September 22–27 for names including google.com.gh, google.sl, and google.as; it said…
- Chrome blocked identified certificates with CRLSets. Google warned the review may have missed domains and that the blocks do not reliably protect non-Chrome users; Malwarebytes said Google later blocked suspicious certificates for other…
- Google said its own systems were not compromised and the issuing certificate authorities did not act improperly. Malwarebytes added that encryption was not broken.
- Google did not name the attackers or confirm the certificates were used to intercept traffic. BleepingComputer said affected domains were pointed at attacker infrastructure; Ars Technica said domain owners' and DNS operators' own…
- Google advised Certificate Transparency monitoring and restrictive CAA records, including ACME account bindings. Sources disagree on whether CAA can stop issuance during an active DNS hijack or only after control is restored.
- Only Ars Technica compared the case to the 2011 DigiNotar breach, which it said was used against roughly 300,000 users in Iran. No source gave a victim count for this incident.
Coverage timelineoldest first · each row is one article
- · 2d agoChrome's Response to Recent ccTLD Registry Hijacks
Lobsters · security· 78
Attackers hijacked .gh, .sl, and .as registries, issuing unauthorized certificates for Google and other brands.
- · 2d agoHackers obtain counterfeit TLS certificates for Google and other large services
Ars Technica · Security· 62
Attackers who hijacked three ccTLD registries passed CA domain validation and obtained fraudulent TLS certificates for Google and other major services.
- · 1d ago