MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via BleepingComputer

Google domains affected by DNS hijacks after ccTLD registry compromises

Attackers breached third-party operators of the .GH, .SL, and .AS country-code registries and changed authoritative DNS records. That let them obtain valid HTTPS certificates for Google domains and other organizations, enabling impersonation and arbitrary content delivery. Google said its own systems were not compromised and blocked the unauthorized certificates in Chrome while working with certificate authorities to revoke them.

Expanded Detail

Attackers gained control over DNS settings for three country-code top-level domains by targeting outside operators: Ghana's .GH, Sierra Leone's .SL, and American Samoa's .AS. That access let them redirect domains and obtain trusted TLS certificates for Google properties and other organizations, which could support impersonation or serving arbitrary content.

Google said its own infrastructure was untouched. It used Chrome's CRLSets to block unauthorized certificates, coordinated revocation with issuing authorities, and reviewed Certificate Transparency logs to find and block more certificates tied to the campaign. It also advised domain owners to watch CT logs and use CAA records.

Context

The incident may erode trust in domain validation and certificate issuance, potentially affecting anyone visiting compromised .GH, .SL, or .AS sites. Chrome users could receive some protection through CRLSets, but people using other browsers may remain exposed. Organizations with domains in those registries could face impersonation or manipulated content risks, while certificate authorities and registries may face pressure to strengthen oversight of third-party operators.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Registry Breaches in Three ccTLDs Enabled Rogue HTTPS Certificates for Google Domains · Cybersecurity
Ongoing FortiBleed Campaign Leaves Organizations Locked Out of Their Own Firewalls · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers hijack Google domains after breaching ccTLD registries.” Browse more stories.