BleepingComputer πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party o

Hackers hijack Google domains after breaching ccTLD registries

  • October 7, 2026
  • 04:50 PM

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.

Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but "did not involve a compromise of Google’s systems."

By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don't own.

CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.

Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.

This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.

Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.

The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.

After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.

β€œFollowing our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained.

β€œTo ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”

CRLSets is a Chrome β€œemergency mechanism” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.

However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.

The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.

β€œDue to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.

Google urges domain owners to:

  • Monitor CT logs across their entire domain portfolio, including parked domains.
  • Publish restrictive Certification Authority Authorization (CAA) records as needed to limit issuance to authorized ACME accounts and validation methods.

Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.

The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.

Build your security blueprint for AI-powered attacks

Join Mikko HyppΓΆnen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat
πŸ“° Read the original article on BleepingComputer

Originally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.