Hackers have successfully hijacked three top-level domain (TLD) registries, allowing them to obtain digital certificates for several Google domains. The affected registries are .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). This brazen attack has left security experts scrambling to understand the scope of the breach and its potential impact on online trust.
The hackers exploited a vulnerability in the TLD registry system, which allows them to issue digital certificates for domains not under their control. In this case, they used the compromised registries to obtain Extended Validation (EV) certificates for several Google domains, including google.com.gh and google.sl. These certificates are designed to verify the identity of website owners and prevent phishing attacks.
The attack is significant because it demonstrates a previously unknown vulnerability in the TLD registry system. The security community has long relied on the integrity of these registries to ensure online trust. With hackers now able to manipulate the system, the very foundation of internet security is at risk. This breach also highlights the importance of secure certificate issuance and verification processes.
The hijacked registries are managed by various organizations, including the Ghana Internet Registry (GIR) and the American Samoa Domain Name Authority (ASDNA). While the extent of the breach is still unclear, it’s evident that hackers have been able to exploit a critical vulnerability in the system. The fact that several Google domains were targeted suggests that the attackers may be seeking to compromise sensitive information or disrupt online services.
The impact of this attack will likely be felt across the cybersecurity community. As the internet becomes increasingly reliant on digital certificates, any breach of trust can have far-reaching consequences. Online businesses and individuals must remain vigilant in verifying the authenticity of website certificates and ensuring their own systems are secure against potential attacks.
In light of this incident, it’s essential for website owners to review their certificate issuance processes and ensure they’re using reputable Certificate Authorities (CAs). Users should also be cautious when visiting websites with untrusted or expired certificates. By taking these precautions, we can mitigate the risks associated with this breach and maintain online trust.
Source: The Hacker News — 2026-10-07