ATTACKER activity targeted three country-code top-level domain registries, hijacking the namespaces for .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). By altering authoritative DNS records, the attackers created conditions whereby HTTPS certificates could be issued for Google properties and other organisations’ sites under those ccTLDs without immediately triggering system-wide alerts.
Google states there was no compromise of its own infrastructure, and that the certificate authorities (CAs) involved did not appear to have acted improperly. The incident underscores how DNS-level control can impact HTTPS trust even when a target’s own systems remain secure.
Chrome responded by blocking the unauthorized certificates through CRLSets and worked with issuing CAs to revoke them, protecting users of Chrome and other clients. Certificate Transparency logs later indicated additional organisations affected, though Google did not disclose the identities or quantities of certificates involved. Google warned that browser-side blocking is not a comprehensive safeguard, and that monitoring CT logs across entire domain portfolios is essential.
The company also recommended adopting more restrictive CAA records with Automatic Certificate Management Environment (ACME) account bindings; while CAA cannot stop issuance during an active DNS hijack, tightening policy afterwards helps prevent reuse of cached domain-control validation checks. Google said it will pursue broader HTTPS ecosystem changes, including reducing certificate validity periods and limiting domain-control validation reuse.