Google Domains Hit by Country-Code Top-Level Domain Hijacks, Leaving Users Vulnerable
Last week, Google disclosed that several of its domains were compromised in a recent hijack of country-code top-level domains (ccTLDs). The affected ccTLDs include .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa), putting all domains with those suffixes at risk. This incident highlights the vulnerabilities that can arise when attackers target the underlying infrastructure of the internet.
In a hijack, an attacker gains control over a domain’s DNS records, allowing them to manipulate traffic and intercept sensitive information. In this case, the attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as those belonging to other organizations. These certificates are used to establish secure connections between websites and browsers, but in this instance, they were issued without proper validation.
Google took swift action once it became aware of the incident, blocking the unauthorized certificates for its domains in Chrome and working with the issuing Certification Authorities (CAs) to revoke them. However, analysis of Certificate Transparency (CT) log data revealed that multiple other organizations had also been affected by this hijack. It is likely that some of these organizations may still be vulnerable, as the attackers could have used cached validation state to mint new certificates after regaining control over the DNS records.
To mitigate this risk, Google encourages domain owners to monitor CT logs for all their domains, especially those in .gh, .sl, or .as. Additionally, publishing restrictive CAA (Certificate Authority Authorization) DNS records can ensure safeguards are in place once DNS control has been restored. This involves restricting issuance of certificates to specific authorized accounts and validation methods, preventing attackers from using cached validation state to mint new certificates.
The incident serves as a reminder that the security of internet infrastructure is only as strong as its weakest link. Country-code top-level domains are often managed by local authorities or organizations with varying levels of expertise and resources. This can create opportunities for attackers to exploit vulnerabilities in these systems, compromising not just individual domains but also the entire ecosystem.
As online services continue to rely on secure connections, it is essential that domain owners and administrators take proactive steps to protect their domains from such attacks. By staying vigilant and monitoring CT logs, as well as publishing restrictive CAA records, organizations can reduce their exposure to these types of threats and ensure a safer online experience for their users.
In the wake of this incident, it’s crucial for all domain owners to review their security measures and take steps to prevent similar hijacks. This includes regularly monitoring DNS records, keeping software up-to-date, and implementing robust access controls. By doing so, we can build a more secure internet infrastructure that protects not just individual domains but the entire online community.
Source: SecurityWeek — 2026-10-09