A sophisticated hacking operation has compromised several country-code top-level domains (ccTLDs), allowing attackers to hijack Google’s domains in Ghana, American Samoa, and Sierra Leone. The breach not only affected Google but also other organizations within these ccTLDs, highlighting a critical vulnerability in the way domain name system (DNS) records are managed.
The attack began with hackers breaching third-party operators that manage ccTLD registries. Once inside, they modified authoritative DNS records to point domains to infrastructure controlled by the attackers. This allowed them to request HTTPS certificates from Certificate Authorities (CAs), which were issued after verifying ownership of the domain. In reality, the hackers had already compromised the DNS system and could manipulate the validation process.
By obtaining these certificates, the attackers were able to impersonate legitimate brands and serve arbitrary content from affected domains. Google immediately responded by blocking the unauthorized certificates for its properties in Chrome through CRLSets, a mechanism designed to quickly block selected revoked or untrusted HTTPS certificates. The company also worked with issuing authorities to revoke the certificates, extending protection to other clients.
However, an examination of Certificate Transparency (CT) logs revealed additional organizations affected by the same attacks, including leading global brands and online services. Google proactively blocked these certificates in Chrome to ensure users’ safety. Despite its efforts, Google warns that it may not have identified every affected domain, leaving some users vulnerable to potential threats.
The incident underscores the importance of secure DNS management practices. To mitigate similar attacks, domain owners are advised to monitor CT logs across their entire portfolio, including parked domains. Additionally, publishing restrictive Certification Authority Authorization (CAA) records can limit issuance to authorized ACME accounts and validation methods. Although CAA records cannot prevent certificate issuance during an active DNS hijack, they do prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored.
As the cybersecurity landscape continues to evolve, it’s essential for organizations to prioritize robust security measures, including secure DNS management. Google’s response to this incident demonstrates its commitment to protecting users and highlights the importance of vigilance in defending against sophisticated attacks.
Source: Bleeping Computer — 2026-10-07