Security News

Attackers Hijack Country Domains to Fake Google Security Certificates

The Register · 8 Oct 2026
Key Takeaway If your business uses a country-code domain, review your DNS records and registrar account security now, and do not assume browser warnings will catch impersonation of your brand.

Google has warned that attackers hijacked three country-code top-level domains: .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). Google said it became aware of the attacks last week. During the hijacks, the attackers changed authoritative DNS records, which control where web traffic is sent, and obtained unauthorised HTTPS certificates for several Google domains as well as domains belonging to other organisations. Google did not say which specific domains or organisations were affected.

The danger is that a visitor could type a correct address and be sent to a criminal's copy of the site without any browser warning appearing. Because the attacker controls both the traffic routing and the private key tied to the fake certificate, they could potentially intercept or alter data users send to the impersonated site. They could also abuse a trusted brand to spread malware or run phishing attacks.

Google said its own systems were not compromised, and Chrome has blocked suspected counterfeit certificates across the affected domains. It also said it has no reason to believe the certificate authorities that issued the certificates did anything wrong. However, Google cautioned domain owners not to rely on browser protections alone. It cannot guarantee it has identified every affected domain, and Chrome's interventions do not reliably protect people who use other browsers.

DNS hijacking HTTPS certificates Google ccTLD Brand impersonation

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.