Threat Intelligence

Hijacked Country Domains Used to Obtain Fake HTTPS Certificates for Google Sites

The Hacker News · 8 Oct 2026
Key Takeaway Keep browsers and devices updated so emergency certificate blocks reach you, and ask your domain provider about registry lock and DNS change alerts for your own domains.

Attackers compromised three country-code top-level domains (.gh for Ghana, .sl for Sierra Leone and .as for American Samoa) and used them to obtain unauthorised HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached. However, with such a certificate, an attacker could pose as the real site over an encrypted connection and read private data sent to it.

Certificate Transparency logs, the public record of issued certificates, show at least 12 certificates issued between September 22 and 27 for Google and YouTube names under the three domains, including google.com.gh, google.sl and google.as. The Hacker News found them on October 7. Let's Encrypt issued 11 and ZeroSSL issued one. All were domain-validated, meaning the applicant only had to show control of the domain. The attackers changed authoritative DNS records during the hijacks, and Google has no reason to believe the certificate authorities did anything wrong.

Chrome blocked the certificates through CRLSets, its emergency blocking method. Google also worked with the certificate authorities to have the certificates revoked, which is meant to protect users of other browsers and apps. A Let's Encrypt staff member confirmed on October 7 that certificates for Google and YouTube were issued and have been revoked. Google did not name the affected domains.

HTTPS certificates DNS hijacking Google Certificate Transparency

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.