DNS Hijacks of Ghana, Sierra Leone, and American Samoa Domains Yield Forged Google Certificates

3 min read
Source: The Register
DNS Hijacks of Ghana, Sierra Leone, and American Samoa Domains Yield Forged Google Certificates
Photo: The Register
TL;DR

Attackers compromised the registries for the .gh, .sl, and .as country-code top-level domains to issue unauthorized TLS certificates for Google and other major brands. Google blocked these forged credentials in Chrome and revoked them via certificate authorities, warning that browser-side fixes alone are insufficient for long-term protection.

Key points

  • Attackers hijacked the .gh, .sl, and .as ccTLD registries to modify DNS records and pass domain control validation checks.
  • At least 12 unauthorized certificates for Google and YouTube domains were issued between September 22 and 27, 2026, primarily by Let's Encrypt.
  • Google updated Chrome to block the identified certificates and worked with certificate authorities to revoke them, though it did not name the other affected organizations.
  • Google advised domain owners to monitor Certificate Transparency logs and publish strict CAA records, as browser-side interventions do not protect non-Chrome users.
  • The incident did not compromise Google's own infrastructure or the certificate authorities, which followed standard validation procedures based on the altered DNS records.

Background

This incident follows a pattern of certificate forgery seen in 2011 when the DigiNotar breach allowed attackers to mint counterfeit certificates for Google and over 200 other domains. Recent archive coverage from October 6 and 8, 2026, already highlighted the hijacking of these specific ccTLDs and Google's initial response, establishing this as an ongoing security concern regarding third-party registry vulnerabilities.

How outlets are covering it

Ars Technica emphasizes the cryptographic implications, noting that possession of unauthorized certificates allows attackers to cryptographically impersonate affected infrastructure. The Hacker News provides granular technical details, identifying 12 specific certificates issued by Let's Encrypt and ZeroSSL, and highlighting the timeline of revocation. Tech Labari focuses on the structural weakness of small ccTLD registries, particularly in Africa, noting that limited security budgets leave national domains vulnerable despite strong security at the brand level. All sources agree that Google's systems were not directly breached, but they differ in emphasis: Ars highlights the impersonation risk, The Hacker News details the certificate logs, and Tech Labari stresses the broader impact on African digital infrastructure.

Why it matters

This incident exposes a critical vulnerability in the DNS ecosystem, where compromised ccTLD registries can be used to issue fraudulent certificates for high-profile brands. It underscores the limitations of browser-side protections and the need for proactive domain monitoring and strict CAA records to prevent unauthorized certificate issuance.

What to watch

Domain owners are advised to monitor Certificate Transparency logs for unexpected certificate issuance and publish restrictive CAA records to prevent attackers from reusing cached validation data. Google is working with the industry to shorten certificate validity periods and limit the reuse of past domain checks, with specific changes scheduled for 2027 and 2029.

Share this article

Want the full story? Read the original reporting

Read on The Register