Security News

Attackers hijack three country domain registries to obtain fake certificates for Google and YouTube

iTnews · 8 Oct 2026
Key Takeaway Keep browsers and security tools updated so they receive blocklists of fraudulent certificates, and do not treat a padlock alone as proof that a site is genuine.

Unknown attackers have hijacked the country top level domain registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as). They then obtained trusted web certificates for major brand sites, including Google and YouTube. Google Security reported the hijacks, and its Chrome browser immediately blocked the invalid certificates that impersonated Google. A check by iTnews of public certificate transparency logs, compared with the Chrome blocklist, found 32 certificates issued to the attackers between 22 and 27 September.

Google said the attackers modified authoritative DNS records and obtained unauthorised HTTPS certificates for several Google domains and those of other organisations. Certificate authorities confirm domain control by checking DNS, so changing those records allowed the attackers to pass the checks. Google said it has no reason to believe the authorities that issued the certificates did anything wrong. The certificates came from Let's Encrypt, ZeroSSL and Cloudflare, and all have now been revoked. Most were issued within a 90 minute window on each of the three days.

The risk is that a trusted certificate lets a site show a padlock, so if an attacker can also redirect a user's traffic, even a well-known brand can be impersonated without any browser warning. iTnews contacted the registry operators but received no responses.

DNS hijacking TLS certificates Google Chrome ccTLD

Summarised by CISO AI from iTnews, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.