Google: attackers hijacked the .gh, .sl and .as country-code domain registries, changed DNS for selected domains and obtained unauthorised HTTPS certificates for several Google domains and other major brands; Chrome blocked them via CRLSets
Google said on 6 October 2026 that the previous week it became aware of a series of hijacks of three country-code top-level domains: .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). The attackers compromised the third-party registries rather than Google or the domain owners, changed the authoritative DNS records for selected domains under those suffixes, and used that control to pass certificate authority domain validation and obtain HTTPS certificates covering several Google domains and domains of other organisations. Google says it has no reason to believe the issuing certificate authorities did anything wrong. Chrome blocked the unauthorised certificates for Google properties through its CRLSets mechanism and Google worked with the issuing CAs to revoke them for other clients. Certificate Transparency log data then showed more affected organisations, including several leading global brands and widely used online services, and Chrome blocked those certificates as well, with Google contacting affected organisations where it could. Google has not named the affected domains or said how many certificates were issued, and it warns that its analysis may not have found every affected domain and that Chrome's blocking does not protect users of other browsers. Primary: Google (Chrome Security blog); wire: Ars Technica.
- Product
- Domains under the .gh, .sl and .as ccTLDs; publicly trusted HTTPS (TLS) certificates
- Versions
- n/a — registry and DNS hijack; no product CVE
- Exploited in Australia?
- unknown
- Patch to
- Monitor Certificate Transparency logs for every domain you own, including parked, regional and country-code domains, and alert on any certificate you did not request. Publish restrictive CAA records naming only the CAs you use, with ACME account binding where your CA supports it. If you hold .gh, .sl or .as domains, check their current NS and DNS records against your own records and review recent certificate issuance for them. Do not rely on browser blocking alone, since other clients may still trust a mis-issued certificate.
Primary: Google — Chrome's response to recent ccTLD registry hijacks (6 Oct 2026) · Ars Technica — Hackers obtain counterfeit TLS certificates for Google and other large services (6 Oct 2026)
