Attackers Hijack Three Country-Code Registries to Forge Google TLS Certificates
Google has confirmed that a threat actor compromised third-party DNS operators behind three country-code top-level domain (ccTLD) registries — .GH (Ghana), .SL (Sierra Leone), and .AS (American Samoa) — and used the access to modify authoritative DNS records and obtain fraudulent HTTPS certificates for Google and YouTube domain names. Certificate Transparency (CT) logs show at least 12 certificates were issued across seven domains between September 22 and 27, 2026, including google.com.gh, youtube.com.gh, google.sl, youtube.sl, google.com.sl, google.as, and youtube.as. Google says the incident "did not involve a compromise of Google's systems" — the attackers never touched Google's own infrastructure — but the forged certificates would have let them impersonate Google and YouTube to any visitor whose traffic they could intercept or redirect within those ccTLD namespaces.
Incident Details
| Attribute | Value |
|---|---|
| Affected registries | .GH (Ghana), .SL (Sierra Leone), .AS (American Samoa) |
| Root cause | Compromise of third-party DNS operators managing the ccTLD registries |
| Attack method | Modification of authoritative DNS records to pass domain-control validation (DCV) |
| Certificates issued | At least 12, covering 7 domains/subdomains |
| Certificate Authorities | Let's Encrypt (11 certificates), ZeroSSL (1 certificate) |
| Issuance window | September 22 – September 27, 2026 |
| Domains covered | google.com.gh, youtube.com.gh, google.sl, youtube.sl, google.com.sl, google.as, youtube.as |
| Revocation timeline | .GH certificates revoked ~36 hours after issuance (Sept 26); .AS certificates took ~5 days (Oct 1) |
| Google systems compromised | No — Google states its own infrastructure was not breached |
| Attribution | Not disclosed by Google at time of writing |
| Broader impact | CT logs point to additional, unnamed "global brands and widely used online services" hit by the same campaign |
How the Attack Worked
Compromising the Registry Operators
Rather than attacking Google directly, the threat actor targeted the third-party DNS operators that manage the authoritative name servers for the .GH, .SL, and .AS ccTLDs. Google has not disclosed how these operators were initially compromised — whether through stolen credentials, a vulnerable admin panel, or another vector — nor when the access began. What is clear is that once inside, the attacker could edit authoritative DNS records for any domain registered under those three ccTLDs, including domains Google itself holds for localized services (such as google.com.gh).
Weaponizing Domain-Control Validation
Modern Certificate Authorities issue domain-validated (DV) TLS certificates after a requester proves control of a domain, typically by publishing a specific TXT record or HTTP token that the CA can verify via DNS or web lookup. Because the attacker controlled the authoritative DNS records for the targeted domains, they could trivially satisfy this check — the CA had no way to distinguish a legitimate request from a hijacked one. Using this access, the attacker requested and received valid certificates from Let's Encrypt and ZeroSSL for Google- and YouTube-branded domains under .GH, .SL, and .AS, with issuance dates clustering around September 22, 25, and 27. Google said it has "no reason to believe the issuing CAs acted improperly" — the CAs followed standard validation procedures and were themselves deceived by the DNS manipulation.
What the Certificates Enabled
A valid, browser-trusted TLS certificate for a domain like google.com.gh would let an attacker stand up a convincing phishing or interception point that displays no certificate warning, since the certificate chain validates normally. Combined with the DNS hijack itself — which let the attacker point the domain to infrastructure they controlled — this created a window in which visitors to the affected domains could have been served attacker-controlled content, including credential-harvesting pages, while their browser showed a secure padlock.
Discovery and Scope
Google said it learned of the hijacks in the days before its public disclosure and, after reviewing CT logs for certificates issued under the three ccTLDs, identified additional certificates and organizations — described only as "several leading global brands and widely used online services" — that appear to have been targeted by the same campaign. Google has not named these other victims. The company was explicit about the limits of its own visibility, cautioning that it "cannot guarantee that [its] analysis identified every affected domain" and that Chrome's protections do not extend to users of other browsers.
Impact Assessment
| Impact Area | Description |
|---|---|
| Brand impersonation risk | Valid certificates for Google/YouTube-branded domains under .GH, .SL, and .AS could have supported convincing phishing without browser warnings |
| Trust model exposure | Confirms that DNS control, not organizational identity, is the actual basis of domain-validated certificate issuance — any registry-level compromise downstream of a CA undermines that CA's guarantees |
| ccTLD ecosystem risk | Any domain registered under .GH, .SL, or .AS — not just Google's — was exposed to hijacking and certificate fraud for the duration of the registry compromise |
| Incomplete remediation | Google's CT-log-based detection is reactive and admittedly incomplete; victims whose certificates weren't logged or reviewed may remain undetected |
| Cross-browser gap | Chrome's CRLSets block the known bad certificates in Chrome specifically; users of Safari, Firefox, and other browsers were not automatically protected |
| Precedent | Echoes a prior incident in which a certificate was fraudulently issued for google.tg after Togo's .tg registry was compromised, and tracks with the longer-running, state-linked "Sea Turtle" campaign documented by Cisco Talos, which used stolen DNS admin credentials to hijack ccTLD-hosted domains |
Recommendations
For .GH, .SL, and .AS Domain Owners
- Check Certificate Transparency logs now. Visit
crt.shand search for your domain to see every certificate issued against it; flag anything you did not request. - Contact the issuing CA immediately if an unauthorized certificate is found, and request revocation — don't wait for Google or the registry to act on your behalf.
- Add CAA (Certification Authority Authorization) DNS records restricting which CAs are permitted to issue for your domain, reducing the blast radius of any future DNS-level compromise.
For Security Teams and IT Administrators
- Don't rely on CT-log monitoring from vendors alone — set up your own CT log monitoring (e.g., via crt.sh alerts or a commercial CT-monitoring service) for every domain and subdomain your organization owns, including country-specific and localized TLDs.
- Treat DNS registrar and registry-operator accounts as Tier 0 assets. Enforce hardware-backed MFA, restrict administrative access by IP, and audit DNS change logs regularly — this incident, like Sea Turtle before it, began with compromised third-party DNS administration.
- Review DNSSEC deployment status for any domains under affected or at-risk ccTLDs; while DNSSEC would not have fully prevented this attack if the registry operator itself was compromised, it raises the bar against lower-level record tampering.
For End Users
- Do not assume a valid padlock/HTTPS icon guarantees a site is legitimate, particularly for region-specific domains (
.gh,.sl,.as, and other ccTLDs) you don't regularly visit. - Verify unexpected login prompts from Google, YouTube, or other major services through a known, bookmarked URL rather than a link in an email, SMS, or ad — especially one using a country-code domain variant.
- Keep browsers updated to receive CRLSet and similar emergency certificate-revocation updates as quickly as possible.
Key Takeaways
- Attackers compromised third-party DNS operators managing the .GH, .SL, and .AS ccTLD registries and modified authoritative DNS records to pass certificate domain-validation checks.
- At least 12 fraudulent HTTPS certificates covering 7 Google and YouTube domains were issued by Let's Encrypt (11) and ZeroSSL (1) between September 22 and 27, 2026.
- Google's own systems were not breached — the attack exploited DNS control over ccTLD-hosted domains, not any Google infrastructure weakness.
- Google blocked the known-bad certificates in Chrome via CRLSets, worked with the CAs to revoke them, and used CT logs to uncover additional, unnamed victims among "global brands and widely used online services."
- Revocation took between 36 hours and 5 days depending on the registry, and Google acknowledges its detection via CT logs is likely incomplete and does not protect non-Chrome browser users.
- The incident mirrors a prior google.tg certificate fraud case and the longer-running, state-linked Sea Turtle campaign — underscoring that ccTLD registry operators are a recurring soft target for subverting the CA trust model.
Sources
- BleepingComputer — Hackers hijack Google domains after breaching ccTLD registries
- The Hacker News — Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
- Help Net Security — Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains