Skip to content
TrustList
News

Hijacked .gh, .sl and .as domains used to get fake Google certificates

Editorial

By TrustList Editorial

Chrome users are protected automatically, but other browsers and apps may not be. Google urges domain owners to watch certificate logs and restrict which certificate authorities may issue for them.

About Hijacked .gh, .sl and .as domains used to get fake Google certificates

Hijacked .gh, .sl and .as domains used to get fake Google certificates

6 October 2026: Attackers who took over three country-code top-level domain registries, .gh for Ghana, .sl for Sierra Leone and .as for American Samoa, used that control to obtain unauthorised HTTPS certificates for Google properties and for other organisations' domains. Google's Chrome team says it has blocked the certificates it found and that Chrome users need to do nothing. The company says the attacks did not compromise Google's own systems: the target was the registries.

Not yet independently verified. Google does not name the other affected organisations or say how many certificates were issued, and says it cannot guarantee it found every affected domain. The Ars Technica page could not be read by us, so it is cited from its headline only. We will update this when it can be confirmed, and remove this note.

A certificate authority normally issues a certificate once the applicant proves control of a domain, typically through a DNS record. Because the attackers had altered DNS records at the registry level, they could pass that check. Google responded by pushing the certificates covering its own services into CRLSets, the list Chrome uses to block specific certificates without waiting for slower revocation checks, and by asking the issuing certificate authorities to revoke them. It then searched Certificate Transparency logs, found further certificates tied to other organisations, and blocked those in Chrome too.

Google states two limits. Its analysis may not have identified every affected domain, and Chrome's protection does not extend to other clients. Browsers and apps that do not read CRLSets depend on formal revocation by the issuing authority.

The post sets out three steps for domain owners:

  • monitor Certificate Transparency logs across the whole domain portfolio, including regional and parked domains, to catch certificates nobody requested
  • publish restrictive CAA records, with ACME account bindings where possible, so only the authorities you use can issue for your names
  • remember that authorities may reuse an earlier domain validation, so an attacker who passed a check during the hijack may still obtain certificates after DNS control is restored

For the longer term, Google says it will work through the Chrome Root Program to shorten certificate lifetimes and limit how long a validation can be reused.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy