Attackers Forge Google Certificates via Hijacked Country Code Domains

Hackers compromised the .gh, .sl, and .as country code top-level domains to issue unauthorized TLS certificates for Google and other major brands. Google updated Chrome to block these forged credentials and advised domain owners to monitor certificate transparency logs, noting that browser-side fixes alone are insufficient for long-term protection.
Key points
- Attackers gained control of the .gh, .sl, and .as ccTLDs, allowing them to modify authoritative DNS records for specific domains.
- By manipulating DNS records, attackers passed automated domain control validation checks to obtain unauthorized certificates for 'several Google domains' and other global brands.
- Google stated that it did not identify the specific affected domains or the other organizations involved, nor did it disclose the total number of forged certificates issued.
- The company updated Chrome to block all identified unauthorized certificates and worked with certification authorities to revoke them, though the official revocation process remains slow.
- Google emphasized that the incident did not involve a compromise of the affected organizations' infrastructure, and that certificate authorities followed all standard requirements during the issuance process.
Background
This incident echoes the 2011 DigiNotar breach, where attackers minted counterfeit certificates for Google and over 200 other high-traffic domains, impacting hundreds of thousands of users. While previous unauthorized certificate incidents often stemmed from certificate authority failures, this event highlights vulnerabilities in domain registry and DNS control. Recent Google updates, such as the Android Pulse system service and Motion Assist features, have focused on device health and user experience, but this security breach underscores the ongoing risks associated with the cryptographic authentication layer of the internet.
Why it matters
Unauthorized TLS certificates allow attackers to cryptographically impersonate legitimate websites, potentially intercepting traffic or launching phishing attacks. While Chrome users are protected by immediate blocking, non-Chrome users and undiscovered certificates remain at risk. The incident highlights the critical importance of monitoring certificate transparency logs and implementing restrictive Certification Authority Authorization DNS records to prevent attackers from reusing cached validation data after DNS control is restored.
What to watch
Domain owners are advised to monitor certificate transparency logs for unexpected issuance and publish restrictive Certification Authority Authorization DNS records. Google cannot guarantee that all affected domains have been identified, meaning the threat persists for any certificates that remain undiscovered. The slow nature of official certificate revocation processes continues to necessitate quicker browser-level blocking mechanisms as a primary defense.
Want the full story? Read the original reporting
Read on Ars Technica