Google Blocks Counterfeit Certificates After Registry Breach
Google said Tuesday that attackers compromised three country-code domain registries — .gh, .sl, and .as — and used that access to obtain unauthorized TLS certificates for several Google domains and other major services. Google then updated Chrome to block the counterfeit certificates it has identified and worked with other certificate authorities to stop them in other browsers.
The attackers changed DNS records for selected domains and used the resulting control to satisfy certificate authority ownership checks, so the CA issued browser-trusted certificates even though the attackers never owned the sites’ private keys. That matters because a valid-looking certificate can make an impostor domain look legitimate to users and security tools that trust the public certificate chain.
The exposure sits in the registry and PKI control plane, not just on the web server, so organizations that depend on browser-trusted certificates inherit risk from domain-control failures they do not directly manage. Google also said it cannot be certain it has found every counterfeit certificate, so the full blast radius is still unsettled.