Google domains affected by DNS hijacks after ccTLD registry compromises
Attackers breached third-party operators of the .GH, .SL, and .AS country-code registries and changed authoritative DNS records. That let them obtain valid HTTPS certificates for Google domains and other organizations, enabling impersonation and arbitrary content delivery. Google said its own systems were not compromised and blocked the unauthorized certificates in Chrome while working with certificate authorities to revoke them.
Attackers gained control over DNS settings for three country-code top-level domains by targeting outside operators: Ghana's .GH, Sierra Leone's .SL, and American Samoa's .AS. That access let them redirect domains and obtain trusted TLS certificates for Google properties and other organizations, which could support impersonation or serving arbitrary content.
Google said its own infrastructure was untouched. It used Chrome's CRLSets to block unauthorized certificates, coordinated revocation with issuing authorities, and reviewed Certificate Transparency logs to find and block more certificates tied to the campaign. It also advised domain owners to watch CT logs and use CAA records.
The incident may erode trust in domain validation and certificate issuance, potentially affecting anyone visiting compromised .GH, .SL, or .AS sites. Chrome users could receive some protection through CRLSets, but people using other browsers may remain exposed. Organizations with domains in those registries could face impersonation or manipulated content risks, while certificate authorities and registries may face pressure to strengthen oversight of third-party operators.