NEWS

Hackers Hijack Google Domains After Breaching ccTLD Registries

Attackers breached .gh, .sl, and .as ccTLD registries, forging 12 HTTPS certificates for Google and YouTube domains between Sept 22-27, 2026.

Dylan H.

News Desk

October 7, 2026
8 min read
Hackers Hijack Google Domains After Breaching ccTLD Registries

Attackers Hijack Three Country-Code Registries to Forge Google TLS Certificates

Google has confirmed that a threat actor compromised third-party DNS operators behind three country-code top-level domain (ccTLD) registries — .GH (Ghana), .SL (Sierra Leone), and .AS (American Samoa) — and used the access to modify authoritative DNS records and obtain fraudulent HTTPS certificates for Google and YouTube domain names. Certificate Transparency (CT) logs show at least 12 certificates were issued across seven domains between September 22 and 27, 2026, including google.com.gh, youtube.com.gh, google.sl, youtube.sl, google.com.sl, google.as, and youtube.as. Google says the incident "did not involve a compromise of Google's systems" — the attackers never touched Google's own infrastructure — but the forged certificates would have let them impersonate Google and YouTube to any visitor whose traffic they could intercept or redirect within those ccTLD namespaces.


Incident Details

AttributeValue
Affected registries.GH (Ghana), .SL (Sierra Leone), .AS (American Samoa)
Root causeCompromise of third-party DNS operators managing the ccTLD registries
Attack methodModification of authoritative DNS records to pass domain-control validation (DCV)
Certificates issuedAt least 12, covering 7 domains/subdomains
Certificate AuthoritiesLet's Encrypt (11 certificates), ZeroSSL (1 certificate)
Issuance windowSeptember 22 – September 27, 2026
Domains coveredgoogle.com.gh, youtube.com.gh, google.sl, youtube.sl, google.com.sl, google.as, youtube.as
Revocation timeline.GH certificates revoked ~36 hours after issuance (Sept 26); .AS certificates took ~5 days (Oct 1)
Google systems compromisedNo — Google states its own infrastructure was not breached
AttributionNot disclosed by Google at time of writing
Broader impactCT logs point to additional, unnamed "global brands and widely used online services" hit by the same campaign

How the Attack Worked

Compromising the Registry Operators

Rather than attacking Google directly, the threat actor targeted the third-party DNS operators that manage the authoritative name servers for the .GH, .SL, and .AS ccTLDs. Google has not disclosed how these operators were initially compromised — whether through stolen credentials, a vulnerable admin panel, or another vector — nor when the access began. What is clear is that once inside, the attacker could edit authoritative DNS records for any domain registered under those three ccTLDs, including domains Google itself holds for localized services (such as google.com.gh).

Weaponizing Domain-Control Validation

Modern Certificate Authorities issue domain-validated (DV) TLS certificates after a requester proves control of a domain, typically by publishing a specific TXT record or HTTP token that the CA can verify via DNS or web lookup. Because the attacker controlled the authoritative DNS records for the targeted domains, they could trivially satisfy this check — the CA had no way to distinguish a legitimate request from a hijacked one. Using this access, the attacker requested and received valid certificates from Let's Encrypt and ZeroSSL for Google- and YouTube-branded domains under .GH, .SL, and .AS, with issuance dates clustering around September 22, 25, and 27. Google said it has "no reason to believe the issuing CAs acted improperly" — the CAs followed standard validation procedures and were themselves deceived by the DNS manipulation.

What the Certificates Enabled

A valid, browser-trusted TLS certificate for a domain like google.com.gh would let an attacker stand up a convincing phishing or interception point that displays no certificate warning, since the certificate chain validates normally. Combined with the DNS hijack itself — which let the attacker point the domain to infrastructure they controlled — this created a window in which visitors to the affected domains could have been served attacker-controlled content, including credential-harvesting pages, while their browser showed a secure padlock.

Discovery and Scope

Google said it learned of the hijacks in the days before its public disclosure and, after reviewing CT logs for certificates issued under the three ccTLDs, identified additional certificates and organizations — described only as "several leading global brands and widely used online services" — that appear to have been targeted by the same campaign. Google has not named these other victims. The company was explicit about the limits of its own visibility, cautioning that it "cannot guarantee that [its] analysis identified every affected domain" and that Chrome's protections do not extend to users of other browsers.


Impact Assessment

Impact AreaDescription
Brand impersonation riskValid certificates for Google/YouTube-branded domains under .GH, .SL, and .AS could have supported convincing phishing without browser warnings
Trust model exposureConfirms that DNS control, not organizational identity, is the actual basis of domain-validated certificate issuance — any registry-level compromise downstream of a CA undermines that CA's guarantees
ccTLD ecosystem riskAny domain registered under .GH, .SL, or .AS — not just Google's — was exposed to hijacking and certificate fraud for the duration of the registry compromise
Incomplete remediationGoogle's CT-log-based detection is reactive and admittedly incomplete; victims whose certificates weren't logged or reviewed may remain undetected
Cross-browser gapChrome's CRLSets block the known bad certificates in Chrome specifically; users of Safari, Firefox, and other browsers were not automatically protected
PrecedentEchoes a prior incident in which a certificate was fraudulently issued for google.tg after Togo's .tg registry was compromised, and tracks with the longer-running, state-linked "Sea Turtle" campaign documented by Cisco Talos, which used stolen DNS admin credentials to hijack ccTLD-hosted domains

Recommendations

For .GH, .SL, and .AS Domain Owners

  • Check Certificate Transparency logs now. Visit crt.sh and search for your domain to see every certificate issued against it; flag anything you did not request.
  • Contact the issuing CA immediately if an unauthorized certificate is found, and request revocation — don't wait for Google or the registry to act on your behalf.
  • Add CAA (Certification Authority Authorization) DNS records restricting which CAs are permitted to issue for your domain, reducing the blast radius of any future DNS-level compromise.

For Security Teams and IT Administrators

  • Don't rely on CT-log monitoring from vendors alone — set up your own CT log monitoring (e.g., via crt.sh alerts or a commercial CT-monitoring service) for every domain and subdomain your organization owns, including country-specific and localized TLDs.
  • Treat DNS registrar and registry-operator accounts as Tier 0 assets. Enforce hardware-backed MFA, restrict administrative access by IP, and audit DNS change logs regularly — this incident, like Sea Turtle before it, began with compromised third-party DNS administration.
  • Review DNSSEC deployment status for any domains under affected or at-risk ccTLDs; while DNSSEC would not have fully prevented this attack if the registry operator itself was compromised, it raises the bar against lower-level record tampering.

For End Users

  • Do not assume a valid padlock/HTTPS icon guarantees a site is legitimate, particularly for region-specific domains (.gh, .sl, .as, and other ccTLDs) you don't regularly visit.
  • Verify unexpected login prompts from Google, YouTube, or other major services through a known, bookmarked URL rather than a link in an email, SMS, or ad — especially one using a country-code domain variant.
  • Keep browsers updated to receive CRLSet and similar emergency certificate-revocation updates as quickly as possible.

Key Takeaways

  1. Attackers compromised third-party DNS operators managing the .GH, .SL, and .AS ccTLD registries and modified authoritative DNS records to pass certificate domain-validation checks.
  2. At least 12 fraudulent HTTPS certificates covering 7 Google and YouTube domains were issued by Let's Encrypt (11) and ZeroSSL (1) between September 22 and 27, 2026.
  3. Google's own systems were not breached — the attack exploited DNS control over ccTLD-hosted domains, not any Google infrastructure weakness.
  4. Google blocked the known-bad certificates in Chrome via CRLSets, worked with the CAs to revoke them, and used CT logs to uncover additional, unnamed victims among "global brands and widely used online services."
  5. Revocation took between 36 hours and 5 days depending on the registry, and Google acknowledges its detection via CT logs is likely incomplete and does not protect non-Chrome browser users.
  6. The incident mirrors a prior google.tg certificate fraud case and the longer-running, state-linked Sea Turtle campaign — underscoring that ccTLD registry operators are a recurring soft target for subverting the CA trust model.

Sources