Threats · 4h ago
Google said Tuesday that attackers compromised three country-code domain registries — .gh, .sl, and .as — and used that access to obtain unauthorized TLS certificates for several Google domains and other major services. Google then updated Chrome to block the counterfeit certificates it has identified and worked with other certificate authorities to stop them in other browsers.
The attackers changed DNS records for selected domains and used the resulting control to satisfy certificate authority ownership checks, so the CA issued browser-trusted certificates even though the attackers never owned the sites’ private keys. That matters because a valid-looking certificate can make an impostor domain look legitimate to users and security tools that trust the public certificate chain.
The exposure sits in the registry and PKI control plane, not just on the web server, so organizations that depend on browser-trusted certificates inherit risk from domain-control failures they do not directly manage. Google also said it cannot be certain it has found every counterfeit certificate, so the full blast radius is still unsettled.
2 sources covering this story
Attackers hijacked three country-code top-level domains and obtained unauthorized HTTPS certificates for several Google domains.
Hackers obtain counterfeit TLS certificates for Google and other large services
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
Part of the PlainSec briefing for 2026-10-07