www.securityweek.com 9 Oct 2026, 11:43 UTC

Hackers Hijack Three Country Domains to Obtain Rogue HTTPS Certificates

Hackers Hijack Three Country Domains to Obtain Rogue HTTPS Certificates

HACKERS hijacked three country-code top-level domains—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—to obtain unauthorized HTTPS certificates covering a number of Google domains and other organisations’ domains. Google disclosed that the attackers modified authoritative DNS records at these ccTLDs and managed to get certificates for affected sites, prompting immediate action from Google and certificate authorities (CAs). The incident underscores how trust in third‑party registries can translate into broad certificate misuse when DNS control is compromised.

Google acted by blocking the unauthorized certificates in Chrome and coordinating with issuing CAs to revoke them. Certificate Transparency (CT) log analysis indicated that multiple other organisations and well‑known brands were affected as well. In response, Google urged domain owners to monitor CT logs for all their domains, particularly those under .gh, .sl, or .as, and to publish restrictive DNS-based CA/Domain Validation controls (CAA) to limit certificate issuance after DNS restoration.

The company emphasised that CAs can cache and reuse DCV checks, so restoring a restrictive CAA policy helps prevent attackers from minting new certificates once hijacks end. While Google’s actions mitigated immediate risk, it cautioned that some domains might still be affected, and urged vigilance in monitoring CT logs and implementing strong DCV and DNS controls going forward.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline