Attackers Hijack 3 Country-code Registries, Obtain Google Certificates

(1 votes, average: 5.00 out of 5)
ccTLD Registry Breaches 2026

Google revealed on October 6, 2026 that attackers have hijacked the administrators of three country-code domain registries to get illegitimate HTTPS certificates for a number of Google sites and other domain names. Google said it blocked the certificates in Chrome and that its own systems were not breached.

What was targeted

A country-code top-level domain (ccTLD) is the domain ending that’s assigned to countries or territories, such as .co. The affected ones are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). They’re all at risk if registry operators are compromised, whether the domain is owned by a different person.

HTTPS certificates are digital certificates that enable browsers to verify the identity of a site and encrypt a website’s traffic. They are certificates issued by a certificate authority (CA) following confirmation that the requester owns the domain.

Also Read: What is DNS Poisoning or DNS Spoofing?

The way the Attack came about

The attackers changed authoritative DNS records, authoritative parts of a domain, then got the unauthorised certificates, Google said. Ownership is normally confirmed by having the requester publish a random value provided by a CA in DNS.

Usual steps to verify ownership involve requesting the value from the CA and the requester publishing the CA-supplied random value in DNS. Mitigating the records control, therefore, allows an attacker to pass that check if a domain isn’t theirs to control.

The outlet also said that the access would enable attackers to refer the businesses to infrastructure they controlled, to enable them to impersonate brands. Google’s announcement maintains the lens on whether the certificates were installed to spy on communications or contents remains unclear, CyberInsider added.

Response and Unknowns

Google was made aware of the hijacks “last week,” the company said. But it has prevented the Chrome browser from rejecting revoked certificates via CRLSets, a list maintained by the browser to identify them. It also acted on behalf of the issuing CAs to revoke their CA certificates, thereby adding protection for other clients of the CAs.

Other entities, such as major global brands and popular online services, were uncovered by the Certificate Transparency logs, public records of issued certificates. Google restricted those certificates in Chrome and notified the organisations as far as possible. Users of Web browsers other than Chrome don’t need to do anything.

Several facts were not made public: How the registries were compromised, who is responsible, when the attacks started, and how many certificates were issued were not made public, and whether control of the registries has been restored remains silent.

Google also added, “We cannot ensure that we have identified all impacted domains. These blocks are not always effective in blocking other browsers, and the sources state that they don’t know if there were any certificates revoked for the non-Google organisations.

What Should Domain Owners do

  • Monitor CT logs for every domain, including parked and regional ones. This gives near real-time alerts on certificate issuance.
  • If you own .gh, .sl or .as domains, review recent CT entries for unexpected certificates.  These are the namespaces that are hijacked by everybody.
  • Only allow restricted Certificate Authority Authorization (CAA) records to be published for the CAs, containing the information about the validation methods and authorities that are allowed to issue certificates. Once DNS control is returned, this prevents the use of a previously cached validation to get a new certificate. It is not able to prevent issuance during active hijacking.
  • Do not rely on browser blocking alone. Google indicates that its coverage could be incomplete.

Also Read: What Is DNS Protection? Common DNS Attacks and DNS Protection Capabilities

Google stated that there will be long-term fixes such as shorter certificate lifetimes and reducing the reuse of DNS validation, which will come through Google’s Chrome Root Program & new Chrome Quantum-resistant Root Program.

Janki Mehta

Janki Mehta

Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.