securityonline.info 7 Oct 2026, 02:52 UTC

Google Reveals Registry Hijacks Put Three Country Domains at Risk

GOOGLE’S security team has revealed a wave of ccTLD registry hijacks affecting three country-code domains: .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). The attackers compromised registry-level control and, crucially, altered DNS records to enable the issuance of TLS certificates for the tainted domains. With valid certificates in hand, they could point domains to their own servers and hijack user traffic, potentially decrypting it in transit. Google noted that unauthorized certificates appeared for several organisations, including Google itself, underscoring the scale of the impact.

The investigation found no breach of Google’s internal systems or of the certificate authorities’ (CAs) rules. Under the existing CA process, a valid DNS ownership proof can legitimate certificate issuance, so the CAs were not necessarily at fault. In response, Google used Chrome’s CRLSet to revoke many of the rogue certificates and began coordinating with the CAs to revoke them, helping protect other browsers as well.

Google also examined Certificate Transparency logs and warned that other, unnamed brands and services could be affected, meaning some users may encounter Chrome warnings when visiting those sites. For domain owners, the guidance is to monitor certificates and DNS records; if anything unusual is found, revoke the certificates and rectify DNS entries. The article suggests owners of .gh, .sl, and .as domains consult crt[.]sh to identify issued certificates and act quickly to remove any they did not request.

View full article

Article by CyberSIXT