Cyber Threat Intel 5 min read

Hijacked Domain Registries Let Attackers Get Real HTTPS Certificates for Google Domains

The operators behind Ghana, Sierra Leone and American Samoa's domains were compromised. Chrome has blocked the fraudulently obtained certificates, but Google says it may not have found them all.

Priya Nair
Data, AI Governance & Policy Analyst
Published 8 Oct 2026, 9:56 AM (SGT)
Share:
A smartphone showing the Chrome browser logo A smartphone showing the Chrome browser logo Photo by deepanker70 on Pixabay
Advertisement

8 OCT 2026 — Attackers who broke into the operators of three national domain registries used that access to obtain valid HTTPS certificates for Google and YouTube addresses in Ghana, Sierra Leone and American Samoa. Google says its own systems were not breached, and Chrome has blocked the certificates. But the attack shows how far a website's security depends on a registry its owner does not control.

Google disclosed the hijacks of the .gh, .sl and .as country-code domains in a post on 6 October, saying it learned of them the week before.

What the attackers did

The attackers did not hack Google. They compromised the third-party operators that run the three country-code top-level domains, which put "any domain ending in .gh, .sl, or .as at risk", according to Google's Chrome Secure Web and Networking Team. From there they changed authoritative DNS records, the entries that tell the internet where a domain lives.

Control of the DNS records let them pass the automated checks certificate authorities use to confirm domain control, and so obtain genuine certificates. Google says it has "no reason to believe" the issuers "did anything wrong".

A certificate like that lets an attacker pose convincingly as the real site over an encrypted connection, provided they can also route visitors to their own server.

3Country-code registries hijacked: Ghana, Sierra Leone, American Samoa
12Google and YouTube certificates found in public logs by The Hacker News
22-27 SeptWhen those certificates were first logged, one domain at a time
Not statedWho did it, how the registries were breached, or whether they are secure now

What the public logs show

Certificate Transparency logs record every publicly trusted certificate and are open to search. The Hacker News searched a small set of Google and YouTube names and found 12 unauthorised certificates covering seven domains, including google.com.gh, google.sl and google.as. Let's Encrypt issued 11 and ZeroSSL one.

They appeared one country at a time: .gh on 22 September, .sl on 25 September and .as on 27 September. By 7 October all 12 had been revoked, the earliest within about a day and a half and the last nearly a week after issue. Google itself has not named the domains, and the search covered only a handful of names, so the real total may be higher.

Other brands caught up

After blocking the certificates for its own properties, Google says the logs showed other organisations were hit by the same attacks, "including several leading global brands and widely used online services". It blocked those certificates in Chrome too and contacted the owners where it could, but did not name them.

Advertisement

Google says Chrome users need do nothing. But it cautions that "we cannot guarantee that our analysis identified every affected domain", and that blocking in Chrome does not protect people using other browsers. It also worked with the issuing authorities to revoke the certificates for other software.

What domain owners should do

Google gives two steps. First, monitor Certificate Transparency logs for every domain an organisation owns, including parked domains and regional country-code versions; anyone with a .gh, .sl or .as domain should check recent entries now.

Second, publish a restrictive CAA record, a DNS entry naming which certificate authorities may issue for a domain. Google concedes CAA cannot stop issuance while a hijack is under way. It matters afterwards: authorities may reuse an earlier successful domain check, so an attacker who passed one during the hijack could otherwise obtain more certificates later.

On 8 October, a lookup through Google Public DNS showed all seven affected Google and YouTube domains carrying a CAA record that names only pki.goog, Google's own certificate authority.

The weak link nobody owns

The lesson extends beyond Google. A company can harden its own systems and still lose control of its name if the registry behind that country code is compromised. Google does not say how the operators were breached, whether any certificate was used against visitors, or whether the three registries are now secure.

Google says it will keep pushing changes through its root programme that reduce how long certificates and domain checks can be reused, which would shrink the window an attacker gets from a short-lived hijack.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement