READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Google Says Hackers Hijacked Three Government Domain Registries to Fake TLS Certificates for Google and Other Major Brands

Google Says Hackers Hijacked Three Government Domain Registries to Fake TLS Certificates for Google and Other Major Brands
Attackers took over DNS records for Ghana's .gh, Sierra Leone's .sl, and American Samoa's .as country-code domains, then used that control to trick certificate authorities into issuing fake security certificates for Google and unnamed major brands. Google says it blocked the known fakes in Chrome but admits it cannot guarantee it found every unauthorized certificate or that non-Chrome users are protected.

Google disclosed Tuesday, October 6, that attackers hijacked three country-code top-level domains and used that control to obtain counterfeit TLS certificates impersonating Google and other major online services, according to Ars Technica.

The targeted registries were .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Attackers modified the authoritative DNS records for selected domains within those namespaces, which let them pass the automated domain-control validation checks that certificate authorities rely on before issuing a certificate, Google said.

TLS certificates are what let a browser confirm it's actually talking to google.com and not an impostor. They bind a domain name to a public cryptographic key through a digital signature. When the keys match, the connection is authenticated. Anyone holding an unauthorized certificate for a domain can cryptographically pose as that domain's infrastructure.

How the attack worked

With control of the three ccTLD registries, the attackers could change the IP addresses tied to a selected list of websites and redirect traffic for them, according to Ars Technica and a report from ua.news that cited the same Google statement. That let them modify DNS records and nameserver delegations enough to satisfy certificate authorities' domain-validation requirements, even though they didn't actually own the domains or compromise the targeted companies' own servers.

Google was explicit that this was not a breach of the affected organizations' own infrastructure. The company said certificate authorities followed their required procedures correctly. The failure point was upstream, at the registry level, where DNS records that validation systems trust were altered by someone who shouldn't have had the access.

What Google did, and what it won't say

Google updated Chrome to block every unauthorized certificate it identified and worked with the issuing certificate authorities to get the fake Google certificates formally revoked. Chrome users don't have to do anything, the company said.

But Google has not named which of its own domains were targeted, nor identified any of the other affected companies, despite describing them as "several leading global brands and widely used online services." The number of fraudulent certificates issued in total is also unknown. None of the seven reports reviewed for this story, including coverage from daily.dev and GoKhashtein, could confirm those details, because Google hasn't released them.

Google also undercut its own fix. "Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users," the company said, according to Ars Technica. Formal certificate revocation is slow, which is why browser makers built faster blocking mechanisms, but those mechanisms only work inside the browsers that implement them.

Google's recommended fix for domain owners going forward: monitor Certificate Transparency logs, the public record every publicly trusted certificate must appear in, for issuance they didn't authorize. The company also recommended publishing restrictive Certification Authority Authorization DNS records so attackers can't reuse cached validation data once a hijacked registry is restored to its rightful owner.

Scale is the open question

A discussion thread on the tech forum Tildes raised a fair point. Ghana, Sierra Leone, and American Samoa are not high-traffic internet hubs, and some commenters there questioned how much real-world damage a hijack limited to those three registries could do. The concern about geographic footprint is understandable but doesn't resolve the actual unknowns. Google itself said the counterfeit certificates covered "several leading global brands," not just Ghanaian or Samoan websites, meaning the blast radius isn't defined by where the registries sit but by which global domains routed through them.

GoKhashtein drew a comparison to the 2011 DigiNotar breach, when a compromised Dutch certificate authority issued roughly 500 fraudulent certificates, some of which were reportedly used to intercept traffic for users in Iran. That incident is what pushed the industry to build Certificate Transparency logging in the first place. Whether this latest hijack produces a similar industry response, or whether it's remembered as a contained incident involving three minor registries, depends entirely on information Google has not yet published: which domains were hit, how many certificates were forged, and whether every one of them has actually been revoked.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaHackers obtain counterfeit TLS certificates for Google and other large services
unknown
daily.devHackers obtain counterfeit TLS certificates for Google and other large services
unknown
ua.newsAttackers obtained counterfeit TLS certificates for Google domains
unknown
World Bank DataHackers obtain counterfeit TLS certificates for Google and other large services - Technology data bank
unknown
GoKhashteinDomain Hijacks Expose TLS Certificate Weakness Across Global Brands
unknown
TildesHackers obtain counterfeit TLS certificates for Google and other large services - ~tech
unknown
Moyanai.appHackers obtain counterfeit TLS certificates for Google and other large services