Security

Global Domain Registries Hijacked in Sophisticated Cyberattack, Unauthorized Certificates Issued for Major Brands

By

Server room
Photo via Wikimedia Commons

What happened A sophisticated cyberattack has compromised the digital infrastructure underpinning the country-code top-level domain (ccTLD) registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as). This breach allowed attackers to seize control of authoritative Domain Name System (DNS) records for select domains operating under these national extensions. The incident, disclosed by Google on Tuesday, October 6, 2026, revealed that the attackers leveraged this control to obtain unauthorized HTTPS certificates for several of Google's own domains, as well as for those belonging to other major global brands and widely used online services.

Google clarified that the attacks did not involve a direct compromise of its internal systems. Instead, the perpetrators exploited vulnerabilities within the third-party operators managing these specific ccTLD registries. Upon becoming aware of the hijacks "last week," Google initiated immediate measures to safeguard its users. The company's Chrome browser has since blocked the fraudulent HTTPS certificates through its Certificate Revocation List Sets (CRLSets) and proactively identified and blocked certificates issued to other affected organizations by monitoring Certificate Transparency (CT) logs. Furthermore, Google engaged with the Certificate Authorities (CAs) that issued these unauthorized certificates to ensure their revocation, extending protection to users of other web browsers. This multi-pronged approach aimed to swiftly neutralize the threat and restore trust in the affected domains.

Why it matters The hijacking of domain registries represents a profound and far-reaching threat to internet security and user trust. By gaining unauthorized control over DNS records, attackers can effectively impersonate legitimate websites, redirecting unsuspecting users to malicious sites designed for phishing, malware distribution, or data interception. The issuance of unauthorized HTTPS certificates, which are typically used to verify a website's identity and encrypt communication, lends a false sense of security. When a browser displays a padlock icon, users are led to believe they are interacting with a legitimate, secure site, making it exceedingly difficult for average users to discern authentic online services from fraudulent ones. This type of attack, therefore, not only compromises data but also erodes the fundamental trust users place in the internet's security mechanisms.

The incident underscores the critical importance of robust security practices at every level of the internet's infrastructure, from global tech giants like Google to the often-overlooked national domain registry operators. These registries serve as foundational pillars of the internet, and their compromise can have cascading effects across the digital landscape. While Google has taken swift and decisive action to protect Chrome users, the incident highlights potential vulnerabilities for users relying on other browsers, where similar protective measures might not be as immediately effective or universally applied. The integrity of online transactions, secure communications, and personal data privacy hinges on the unwavering trustworthiness of domain name resolution and certificate issuance processes, making this breach a significant concern for the entire online ecosystem.

Deep dive The attackers' method involved a clever and technically sophisticated manipulation of the internet's established trust mechanisms. By altering the DNS records for targeted domains within the compromised .gh, .sl, and .as registries, they were able to present themselves to legitimate Certificate Authorities (CAs) as the rightful and authorized controllers of those domains. This crucial step allowed them to pass automated domain validation checks, which are standard procedures designed to confirm ownership or control of a domain before issuing a TLS (Transport Layer Security) certificate. Consequently, they obtained what appeared to be legitimate, browser-trusted TLS certificates, complete with the expected security indicators in web browsers.

Google has publicly stated that, given the nature of these attacks, it has no reason to believe the Certificate Authorities that issued the impacted certificates acted improperly or negligently. The CAs, in this scenario, complied with established industry requirements for domain validation, unknowingly issuing certificates to an attacker who had temporarily usurped control of the domain's DNS. This incident serves as a stark reminder that even well-established security protocols, while robust in their design, can be circumvented when foundational elements like domain registries, which are upstream in the trust chain, are compromised. The reliance on DNS for domain validation means that a breach at the registry level can undermine the entire certificate issuance process, creating a critical vulnerability for any domain hosted under that registry.

Report check Reporting from blog.google, helpnetsecurity.com, startupfortune.com, ua.news, atlabyte.com, gurufocus.com, and daily.dev established that attackers successfully hijacked the .gh, .sl, and .as country-code top-level domain registries. These sources confirmed that this allowed attackers to modify authoritative DNS records and obtain unauthorized HTTPS certificates for several Google domains and other major global brands. It was also established that Google disclosed the incident on Tuesday, October 6, 2026, and stated that its own systems were not compromised, but vulnerabilities at third-party ccTLD operators were exploited. Google became aware "last week" and immediately acted, blocking certificates in Chrome via CRLSets and CT logs, and working with CAs for revocation. It is alleged that attackers, by modifying DNS records, presented themselves to legitimate Certificate Authorities as rightful domain controllers to pass automated validation and obtain seemingly legitimate certificates. Google has stated it believes CAs did nothing wrong, as they complied with established requirements.

Open questions Despite Google's swift response and transparency regarding the incident, several critical details surrounding the cyberattack remain unconfirmed or undisclosed to the public. Google has not yet revealed which specific domains under its ownership were affected by the breach, nor has it named the other organizations impacted by these widespread attacks on domain registries. The precise start date of the attacks and the identity of the perpetrators are also still unknown, leaving key questions about the origin and duration of the compromise unanswered. Furthermore, Google has cautioned that it cannot guarantee its analysis has identified every single affected domain or every unauthorized certificate issued through this method, suggesting the full scope of the compromise might be larger than currently understood. The total number of unauthorized certificates issued through this scheme also remains undisclosed. A significant concern is that Google's interventions in Chrome, while effective for its users, do not reliably protect users of other web browsers, leaving a potential gap in broader internet security. As a forward-looking measure, Google strongly advises all domain owners, particularly those operating domains within the .gh, .sl, or .as namespaces, to diligently monitor Certificate Transparency logs for any unexpected certificate issuance. The company also recommends publishing restrictive Certification Authority Authorization (CAA) DNS records as a crucial safeguard once DNS control is fully restored, and to prevent the potential reuse of cached validation data by attackers, thereby adding an extra layer of defense against such sophisticated attacks in the future.