Hackers Hijack Domain Registries to Mint Trusted Certificates for Google and Other Services
Attackers hijacked three country-code domain registries and used control of their DNS records to obtain fraudulent HTTPS certificates for Google, YouTube and other organizations. Google says its systems were not breached, but the incident shows how a compromise of domain infrastructure can undermine the web’s trust system.
What happened
The affected namespaces were .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. According to Google, attackers modified authoritative DNS records after compromising third-party country-code top-level domains. That allowed them to pass automated domain-control checks used by certificate authorities and request HTTPS certificates for selected domains.
Google said the certificate authorities involved appear to have followed their normal validation rules. However, Certificate Transparency records reviewed by The Hacker News showed at least 12 unauthorized certificates covering seven Google and YouTube domains. Let’s Encrypt issued 11 of them and ZeroSSL issued one. The certificates were logged between September 22 and September 27, 2026, and all 12 were shown as revoked by October 7, 2026.
A fraudulent certificate can make an attacker-controlled site appear legitimate to a browser. Combined with DNS manipulation, that could enable phishing, credential theft, malicious downloads or the collection of private information sent to an impersonated site. Google said it also found evidence that other global brands and widely used online services may have been affected, but it did not name them.
Google’s response
Google blocked the unauthorized certificates for its properties through Chrome’s emergency certificate-revocation mechanism, known as CRLSets. It also worked with certificate authorities to revoke the certificates, helping protect people using other browsers and applications. Google says Chrome users do not need to take action.
Google cautioned that browser intervention is not a complete defense. Its analysis may not identify every affected certificate, and Chrome’s protections do not automatically cover users of other browsers or software that maintains its own certificate-validation process.
What website owners should do
- Monitor Certificate Transparency logs. Set alerts for every domain, including parked domains and regional country-code domains. Unexpected certificate issuance should be investigated immediately.
- Publish restrictive CAA records. Certification Authority Authorization records specify which certificate authorities may issue certificates for a domain. Google recommends restrictive policies with authorized account and validation-method bindings when supported.
- Report unauthorized certificates. Contact the issuing certificate authority and file a certificate problem report. Review DNS records after any registry or nameserver incident and confirm that unauthorized changes have been removed.
The episode is a reminder that HTTPS depends on more than encryption. It also depends on accurate DNS control, trustworthy certificate issuance and rapid public detection. Google said it is pursuing longer-term improvements, including shorter certificate lifetimes and reduced reuse of domain-control validation.
References
Fadilpašić, S. (2026, October 8). Google says counterfeit TLS certificates of major services stolen by hackers. TechRadar Pro. https://www.techradar.com/pro/security/google-says-counterfeit-tls-certificates-of-major-services-stolen-by-hackers
Chrome Secure Web and Networking Team. (2026, October 6). Chrome’s response to recent ccTLD registry hijacks. Google Security Blog. https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
Khandelwal, S. (2026, October 7). Attackers hijack .gh, .sl, and .as registries to obtain certificates for Google domains. The Hacker News. https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html?m=1
