MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via The Hacker News

Registry Breaches in Three ccTLDs Enabled Rogue HTTPS Certificates for Google Domains

Image via The Hacker News
Image via The Hacker News

Google reported that attackers took over registry infrastructure for Ghana, Sierra Leone, and American Samoa top-level domains and used it to issue unauthorized TLS certificates for some Google domains. Google's own systems were not compromised, but domains under .gh, .sl, and .as were affected. Such certificates could allow an adversary to impersonate legitimate encrypted websites.

Expanded Detail

This report points to a broader trust problem in encrypted web browsing: certificates are meant to confirm that a site is genuine, but their issuance can be abused when domain registry systems are taken over. According to Google, attackers gained control of registry operations for three country-code top-level domains—Ghana’s .gh, Sierra Leone’s .sl, and American Samoa’s .as—and then obtained certificates for certain Google domains without authorization. Google said its own systems remained secure. The domains involved fall under those three ccTLDs. The case shows how a compromise outside a company’s own network can still affect certificate trust.

Context

The reported breach could affect people and

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains.” Browse more stories.