Security

Hackers hijacked three country domains to get certificates for Google

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • Attackers hijacked the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) registries
  • At least 12 certificates for seven Google and YouTube domains were logged between 22 and 27 September
  • Google blocked them in Chrome and the CAs revoked them, but Google has not said whether any were used
  • Domain owners should watch Certificate Transparency logs and publish a strict CAA record

Google disclosed on 6 October 2026 that attackers had taken over three country-code domain registries and used them to get certificates for Google and YouTube names. The registries were .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). Google says its own systems were not breached.

How the trick works

Certificate authorities issue a domain-validated certificate to whoever can prove control of the domain, usually by answering a check through DNS. If you control the registry above a domain, you can change the authoritative DNS records and pass that check. The attackers did exactly that, which means the certificate authorities followed the rules and still handed out certificates for names like google.com.gh, google.sl, youtube.as and youtube.com.gh.

The Hacker News found at least 12 certificates covering seven domains in public Certificate Transparency logs, logged between 22 and 27 September. Let's Encrypt issued 11 and ZeroSSL issued one. Google says other well-known brands were hit too, but it has not named them.

What happened next

Google blocked the certificates in Chrome using CRLSets and worked with the issuers to revoke them. By 7 October all 12 showed as revoked, three on 26 September and nine on 1 October. That is a gap of between about a day and a half and nearly a week after logging.

Google has not said who was behind it, how the registries were compromised, or whether any certificate was used to impersonate a site or intercept traffic. That last point is the one that matters most, and it is still open.

Why this one is awkward

A certificate for a regional Google domain is only useful against people who visit it, so the direct risk is narrow. The bigger lesson is that the trust chain behind HTTPS is only as strong as the weakest registry in it. Google also warns that Chrome's blocks do not reliably protect people on other browsers, so domain owners should not lean on Chrome to clean up.

The broader fix is shorter validation reuse. CAs can currently reuse a domain check for up to 200 days, falling to 100 days in March 2027 and 10 days in March 2029. Let's Encrypt already reuses checks for 30 days.

What you can do

If you run domains, including parked and regional ones, three jobs are worth an afternoon:

  • Watch Certificate Transparency logs for every name you own.
  • Publish a strict CAA record naming only the CA you use. It cannot stop issuance during an active hijack, but it blocks later issuance once you regain control.
  • If you spot a certificate you did not ask for, file a Certificate Problem Report with the issuer. CAs must give initial findings within 24 hours.

If you only browse, nothing is needed. Keep your browser updated and keep an eye on the zero-day network device checklist for the bigger picture on edge risk.

More from Future Technology