Hijacked .gh, .sl and .as domains used to get fake Google certificates
EditorialBy TrustList Editorial
Chrome users are protected automatically, but other browsers and apps may not be. Google urges domain owners to watch certificate logs and restrict which certificate authorities may issue for them.
- Cybersecurity
- Vulnerability Management
- Ghana
- American Samoa
- +1 more
About Hijacked .gh, .sl and .as domains used to get fake Google certificates
Hijacked .gh, .sl and .as domains used to get fake Google certificates
6 October 2026: Attackers who took over three country-code top-level domain registries, .gh for Ghana, .sl for Sierra Leone and .as for American Samoa, used that control to obtain unauthorised HTTPS certificates for Google properties and for other organisations' domains. Google's Chrome team says it has blocked the certificates it found and that Chrome users need to do nothing. The company says the attacks did not compromise Google's own systems: the target was the registries.
Not yet independently verified. Google does not name the other affected organisations or say how many certificates were issued, and says it cannot guarantee it found every affected domain. The Ars Technica page could not be read by us, so it is cited from its headline only. We will update this when it can be confirmed, and remove this note.
A certificate authority normally issues a certificate once the applicant proves control of a domain, typically through a DNS record. Because the attackers had altered DNS records at the registry level, they could pass that check. Google responded by pushing the certificates covering its own services into CRLSets, the list Chrome uses to block specific certificates without waiting for slower revocation checks, and by asking the issuing certificate authorities to revoke them. It then searched Certificate Transparency logs, found further certificates tied to other organisations, and blocked those in Chrome too.
Google states two limits. Its analysis may not have identified every affected domain, and Chrome's protection does not extend to other clients. Browsers and apps that do not read CRLSets depend on formal revocation by the issuing authority.
The post sets out three steps for domain owners:
- monitor Certificate Transparency logs across the whole domain portfolio, including regional and parked domains, to catch certificates nobody requested
- publish restrictive CAA records, with ACME account bindings where possible, so only the authorities you use can issue for your names
- remember that authorities may reuse an earlier domain validation, so an attacker who passed a check during the hijack may still obtain certificates after DNS control is restored
For the longer term, Google says it will work through the Chrome Root Program to shorten certificate lifetimes and limit how long a validation can be reused.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Ghana
- American Samoa
- Networking
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.