ATTACKERS hijacked three country-code top-level domains—.gh (Ghana), .sl (Sierra Leone) and .as (American Samoa)—and used them to obtain unauthorized HTTPS certificates for Google domains. The certificates, all domain-validated, were issued between 22 and 27 September 2026 and were logged in Certificate Transparency records. Twelve certificates covered seven domains, including wildcards such as *.youtube.com[.]gh and google.com[.]gh, as well as google[.]sl and google[.]as.
Eleven certificates came from Let’s Encrypt and one from ZeroSSL. Google said its own systems were not breached, and the attacker’s aim would have been to impersonate Google sites over TLS and intercept private data if users trusted those certificates.
Evidence and response indicate that attackers changed authoritative DNS records during the hijacks, suggesting DNS-level compromise rather than a flaw at the CAs. Chrome blocked the unauthorized certificates via CRLSets, and Google coordinated with issuing CAs to revoke the certificates, while also alerting other browsers and apps that might have trusted them. CT logs show the certificates appeared on three separate days (one ccTLD per day).
Google recommended domain owners monitor Certificate Transparency logs for certificates they did not request, publish strict CAA records to limit which CAs can issue certificates, and report any unexpected certificates to the issuing CA. The company cautioned that DNS hijacking is complex and Chrome’s blocks do not guarantee protection for users on other browsers.