Google said on 6 October 2026 that attackers compromised the operators of three country-code top-level domains and used that control to obtain unauthorized HTTPS certificates. Google's own systems were not breached. Any name under .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was at risk while the registries were hijacked.
What happened
The attackers changed authoritative DNS records, then passed normal domain-validation checks at certificate authorities. Google says it has no reason to believe the CAs did anything wrong. Chrome blocked the unauthorized certificates for Google domains through CRLSets. Google worked with the CAs to revoke them.
Certificate Transparency logs show at least 12 certificates for seven Google and YouTube names, logged between 22 and 27 September 2026. Let's Encrypt issued 11. ZeroSSL issued one. Names include google.com.gh, google.sl and google.as. All 12 were revoked by 7 October. The shortest gap from first log entry to revocation was about a day and a half. The longest was nearly a week. Google also saw CT evidence that other well-known brands were hit, and did not name them.
Google has not said whether any certificate was used to impersonate a site, who compromised the registries, or whether those registries are fully recovered.
Who is affected
- Anyone who owns a domain under .gh, .sl or .as, including parked names.
- Customers and staff who use sites on those ccTLDs, if a forged certificate was accepted before revocation.
- Other organizations Google believes were targeted. Names were not published.
What to do now
If you own a name under .gh, .sl or .as, review Certificate Transparency logs for certificates you did not request and file a problem report with the issuing CA. Publish a strict CAA record that names only your CA, and tie it to your account if the CA supports that. A CAA record will not stop issuance during an active DNS hijack, but it blocks later certificates that reuse a domain check completed while the attacker had DNS. Chrome users do not need to act for the Google certificates already blocked.
Source: The Hacker News, Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains. Google: Chrome's response to recent ccTLD registry hijacks.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- CVE-2026-102255 CVSS 10.0 SSRF in SonicWall SMA1000 WorkPlace
- PoeLLM hits 3,400 servers mining on exposed LiteLLM and Ollama
- FortiBleed: FBI says 86,644 Fortinet device credentials still in play
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.