8 OCT 2026 — Attackers who broke into the operators of three national domain registries used that access to obtain valid HTTPS certificates for Google and YouTube addresses in Ghana, Sierra Leone and American Samoa. Google says its own systems were not breached, and Chrome has blocked the certificates. But the attack shows how far a website's security depends on a registry its owner does not control.
Google disclosed the hijacks of the .gh, .sl and .as country-code domains in a post on 6 October, saying it learned of them the week before.
What the attackers did
The attackers did not hack Google. They compromised the third-party operators that run the three country-code top-level domains, which put "any domain ending in .gh, .sl, or .as at risk", according to Google's Chrome Secure Web and Networking Team. From there they changed authoritative DNS records, the entries that tell the internet where a domain lives.
Control of the DNS records let them pass the automated checks certificate authorities use to confirm domain control, and so obtain genuine certificates. Google says it has "no reason to believe" the issuers "did anything wrong".
A certificate like that lets an attacker pose convincingly as the real site over an encrypted connection, provided they can also route visitors to their own server.
What the public logs show
Certificate Transparency logs record every publicly trusted certificate and are open to search. The Hacker News searched a small set of Google and YouTube names and found 12 unauthorised certificates covering seven domains, including google.com.gh, google.sl and google.as. Let's Encrypt issued 11 and ZeroSSL one.
They appeared one country at a time: .gh on 22 September, .sl on 25 September and .as on 27 September. By 7 October all 12 had been revoked, the earliest within about a day and a half and the last nearly a week after issue. Google itself has not named the domains, and the search covered only a handful of names, so the real total may be higher.
Other brands caught up
After blocking the certificates for its own properties, Google says the logs showed other organisations were hit by the same attacks, "including several leading global brands and widely used online services". It blocked those certificates in Chrome too and contacted the owners where it could, but did not name them.
Google says Chrome users need do nothing. But it cautions that "we cannot guarantee that our analysis identified every affected domain", and that blocking in Chrome does not protect people using other browsers. It also worked with the issuing authorities to revoke the certificates for other software.
What domain owners should do
Google gives two steps. First, monitor Certificate Transparency logs for every domain an organisation owns, including parked domains and regional country-code versions; anyone with a .gh, .sl or .as domain should check recent entries now.
Second, publish a restrictive CAA record, a DNS entry naming which certificate authorities may issue for a domain. Google concedes CAA cannot stop issuance while a hijack is under way. It matters afterwards: authorities may reuse an earlier successful domain check, so an attacker who passed one during the hijack could otherwise obtain more certificates later.
On 8 October, a lookup through Google Public DNS showed all seven affected Google and YouTube domains carrying a CAA record that names only pki.goog, Google's own certificate authority.
The weak link nobody owns
The lesson extends beyond Google. A company can harden its own systems and still lose control of its name if the registry behind that country code is compromised. Google does not say how the operators were breached, whether any certificate was used against visitors, or whether the three registries are now secure.
Google says it will keep pushing changes through its root programme that reduce how long certificates and domain checks can be reused, which would shrink the window an attacker gets from a short-lived hijack.