Hijacked ccTLD Registries Yielded Certificates for Google Domains

Attackers compromised the registries for the .gh, .sl and .as country-code top-level domains and obtained unauthorized HTTPS certificates for Google and YouTube names, Google said on October 6. Certificate Transparency logs show at least 12 certificates covering seven domains, including google.com.gh, google.sl and google.as, issued between September 22 and 27.
Google said its own systems were not breached. The risk applied to domains in Ghana’s .gh, Sierra Leone’s .sl and American Samoa’s .as zones: a fraudulent certificate could enable an attacker to impersonate a legitimate site over an encrypted connection and collect data sent by users.
Certificates followed DNS changes
The attackers changed authoritative DNS records during the registry hijacks. That gave them the apparent domain control needed to pass domain validation, the process certificate authorities use before issuing a certificate. Google said it had no reason to believe the certificate authorities acted improperly.
Logs reviewed by The Hacker News show that Let’s Encrypt issued 11 of the 12 certificates and ZeroSSL issued one. The entries were logged one country-code domain at a time: .gh on September 22, .sl on September 25 and .as on September 27. The certificates included wildcard names for Google and YouTube, as well as standard names such as www.google.sl.
All 12 certificates had been revoked by October 7. The two .gh certificates and the ZeroSSL certificate were revoked on September 26; the other nine were revoked on October 1. The shortest interval from logging to revocation was roughly a day and a half, while the longest was nearly a week.
Chrome response does not cover every user
Google used Chrome CRLSets to block the unauthorized certificates for its domains, and said it also blocked certificates it identified for other affected organizations. It contacted certificate authorities for revocation and, where possible, notified other organizations. Chrome users do not need to take action, Google said.
That browser-level response is not a substitute for domain-owner controls. Google warned that its analysis might not have identified every affected name and that Chrome’s blocks do not reliably protect users of other browsers or applications. The broader DNS exposure complements DNS attacks affecting internet trust infrastructure by showing how attacks on internet trust infrastructure can affect services beyond a single provider.
Monitoring and CAA remain essential
Google advised owners to monitor Certificate Transparency logs for every domain they hold, including parked domains and regional country-code names, and to report unexpected certificates to the issuing authority. Under the CA/Browser Forum Baseline Requirements, a Certificate Problem Report must receive initial findings from the CA within 24 hours.
It also recommended strict CAA records, which name the certificate authorities permitted to issue for a domain. CAA cannot prevent issuance during a live DNS hijack because an attacker controlling DNS can alter the record. Once the owner regains DNS control, however, strict CAA can prevent reuse of a validation completed by an attacker. For businesses, the practical implication is to treat DNS control, CT alerting and restrictive CAA policy as operational safeguards for every registered domain.

