Hijacked ccTLDs Enable Forged Google Certificates

Attackers compromised the registries for .gh, .sl, and .as country-code top-level domains to issue unauthorized HTTPS certificates for Google and other major brands. Google blocked these certificates in Chrome and revoked them via certificate authorities, warning that browser-side fixes alone are insufficient for long-term protection.
Key points
- Attackers hijacked the .gh, .sl, and .as ccTLD registries to alter DNS records and pass domain control validation checks.
- At least 12 unauthorized certificates were issued for Google and YouTube domains between September 22 and 27, 2026.
- Google blocked the certificates in Chrome using CRLSets and worked with certificate authorities to revoke them.
- The incident did not involve a breach of Google’s own systems or any wrongdoing by the certificate authorities.
- Google advised domain owners to monitor Certificate Transparency logs and publish strict CAA records to prevent future abuse.
Background
This incident follows a pattern of DNS hijacking seen in previous years, such as the 2011 DigiNotar breach, where attackers obtained counterfeit certificates for high-traffic domains. Google has previously emphasized the importance of reducing certificate validity periods and domain control validation reuse to mitigate such risks, as noted in its commitment to long-term HTTPS ecosystem improvements.
How outlets are covering it
The Hacker News provides detailed technical data, including specific certificate fingerprints and issuance dates, highlighting the role of Let's Encrypt and ZeroSSL. Ars Technica emphasizes the cryptographic impersonation risk and the slow revocation process, noting that browser-side blocking is a temporary fix. The Register focuses on the broader impact on other large organizations and the need for domain owners to take proactive measures. Help Net Security summarizes Google’s official response, stressing that the attack did not compromise Google’s systems or the certificate authorities. All sources agree that the incident underscores the vulnerability of ccTLD registries and the importance of Certificate Transparency monitoring.
Why it matters
This incident highlights the critical risk posed by ccTLD registry compromises, which can enable attackers to impersonate major brands and intercept encrypted traffic. It underscores the need for robust DNS security measures, such as strict CAA records and Certificate Transparency monitoring, to protect against unauthorized certificate issuance. The incident also demonstrates the importance of collaboration between browser makers, certificate authorities, and domain owners to mitigate the impact of such attacks.
What to watch
Google will continue to work with the wider community to limit the damage from DNS and routing compromises, including efforts to reduce certificate validity and domain control validation reuse. Domain owners are advised to monitor Certificate Transparency logs and publish strict CAA records to prevent future abuse. The CA/Browser Forum has approved a schedule to reduce the reuse of domain checks, with limits falling to 100 days in March 2027 and 10 days in March 2029.
- Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains The Hacker News
- Hackers obtain counterfeit TLS certificates for Google and other large services Ars Technica
- Attackers hijacked top-level domains, minted fake security certs for Google and other orgs The Register
- Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains Help Net Security
- Hackers obtain HTTPS certificates for Google Techzine Global
Want the full story? Read the original reporting
Read on The Hacker News