Hackers hijack Google domains after breaching ccTLD registries

A sophisticated attack has compromised several country-code top-level domains (ccTLDs), allowing hackers to hijack Google domains and issue unauthorized HTTPS certificates. The attackers breached third-party operators managing ccTLD registries in Ghana, American Samoa, and Sierra Leone, modifying authoritative DNS records to point domains to infrastructure under their control.

This maneuver enabled the threat actor to obtain valid TLS certificates for affected domains, including those belonging to other organizations within these ccTLDs. By impersonating legitimate brands, the attackers could serve arbitrary content from hijacked domains, potentially leading to phishing or malware attacks against unsuspecting visitors.

Google has confirmed that its systems were not compromised in this incident and that it has no reason to believe the issuing Certificate Authorities (CAs) acted improperly. However, the company was forced to take immediate action to mitigate the damage. Google blocked unauthorized certificates for its properties in Chrome through CRLSets, an emergency mechanism designed to allow quick blocking of selected revoked or untrusted HTTPS certificates.

Furthermore, by examining Certificate Transparency (CT) logs, Google identified additional organizations that may have been impacted by these attacks. The company proactively blocked certificates connected to these incidents and notified affected organizations where possible. While Chrome users are protected through CRLSets, Google warns that this solution may not cover all potential threats and that users of other browsers might not be safeguarded.

To protect against similar DNS hijacks in the future, domain owners are advised to monitor CT logs across their entire domain portfolio, including parked domains. Publishing restrictive Certification Authority Authorization (CAA) records can limit issuance to authorized ACME accounts and validation methods. However, Google notes that CAA records cannot prevent certificate issuance during an active DNS hijack but can prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored.

It’s essential for readers to be aware of this incident and take necessary precautions to protect their online presence. For those responsible for managing domains, it’s crucial to stay vigilant and regularly monitor their CT logs. By taking proactive steps, we can reduce the impact of such attacks and keep our digital landscape more secure.


Source: Bleeping Computer — 2026-10-07