Thursday, 8 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

The Register ·
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy.

Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations.

Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs).

“During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” Google security warned on Tuesday.

Google did not say which specific domains or organizations were affected.

The attacks did not compromise Google’s systems, and Chrome quickly blocked suspected counterfeit certificates across the affected ccTLDs - meaning Chrome browser users are already protected - according to the Chocolate Factory.

“Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” the alert said.

These types of attacks allow criminals to impersonate legitimate organizations and websites without triggering any browser security alerts.

The attacker controls the traffic routing (via DNS) and the private key associated with the unauthorized certificate, which means they can potentially intercept or modify data sent by users to the impersonated site - and abuse the trusted organization's brand to distribute malware or conduct phishing attacks.

“While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google warned domain owners.

“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” To ensure that their domains and users are protected, Google recommends ongoing monitoring of Certificate Transparency (CT) logs across all of an organization’s domains, including parked or regional ccTLD properties.

This provides near real-time alerts whenever someone obtains a certificate for one of your domains.

And if you operate a domain in .gh, .sl, or .as, definitely review recent CT log entries for unexpected certificates.

Organizations can also publish restrictive Certification Authority Authorization (CAA) DNS records, which allow domain owners to specify which CAs are permitted to issue certificates for their domains.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›