Google Domains Impacted by Recent ccTLD Hijacks

Google Domains Caught in Crosshairs of Recent ccTLD Hijacks, Leaving Multiple Organizations Exposed

A recent hijack of country-code top-level domains (ccTLDs) has caught several Google domains off guard, exposing them to unauthorized HTTPS certificates. The incident, which occurred last week, targeted the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, putting all domains with those suffixes at risk of compromise.

The attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations. However, according to Google, the Certification Authorities (CAs) that issued the certificates are not to be blamed, given the nature of the attacks. This is because CAs are permitted to cache and reuse completed domain control validation (DCV) checks for subsequent issuance, allowing attackers to exploit this process.

Google quickly sprang into action upon learning of the incident, blocking unauthorized certificates for its domains in Chrome and working with issuing CAs to revoke them. Additionally, analysis of Certificate Transparency (CT) log data revealed that multiple other organizations, including global brands and popular online services, have been affected by these hijacks. To ensure user safety, Google proactively blocked these certificates in Chrome where possible, while also reaching out to impacted organizations to alert them to the findings and actions taken.

The incident highlights the importance of domain security and control validation procedures. Google encourages domain owners to monitor CT logs for all their domains, especially those in .gh, .sl, or .as, and to publish restrictive CAA DNS records to ensure safeguards after DNS control has been restored. This is crucial because even after a hijack ends, an attacker can still use cached validation state to mint new certificates.

In essence, this incident serves as a wake-up call for domain owners to review their security controls and take proactive measures to prevent unauthorized certificate issuance. By implementing restrictive CAA policies and regularly monitoring CT logs, organizations can reduce the risk of falling victim to similar attacks in the future.


Source: SecurityWeek — 2026-10-09