arstechnica.com 6 Oct 2026, 19:21 UTC

Hackers Hijack Country Domains to Forge Google TLS Certificates

CyberSIXT Evidence Panel Source marked as original reporting

HACKERS gained control of three country-code top-level domains by hijacking the registries for .gh, .sl and .as, and then tampering with DNS records to mint counterfeit TLS certificates for several Google domains and other major brands. With this access, the attackers could route traffic to sites they controlled and present forged certificates that browsers would treat as legitimate.

Google said it updated Chrome to block the counterfeit certificates and coordinated with other certificate authorities to encourage browsers to do the same. The company stressed that the DNS-hijack attack and certificate issuance were the weak points in the chain, not a compromise of the registries’ underlying infrastructure or the domain owners’ systems.

Google and others noted that it is unclear how widespread the issuance of unauthorized certificates was, or how many have already been revoked. The process for revoking certificates in browsers can be slow, so a faster browser-level block was implemented for known counterfeit certificates. Google also urged domain owners to review TLS transparency logs for any certificates issued for domains they control, indicating the potential for lingering risk if undiscovered certificates remain active.

The incident demonstrates the persistent risk from certificate authorities and DNS-level manipulation, underscoring why cross‑checking DNS records and certificate issuance remains critical. The piece references prior incidents, including the DigiNotar breach in 2011, to illustrate that misissued certificates have long posed threats to large-scale online services.

View full article

Article by CyberSIXT