Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.
Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but “did not involve a compromise of Google’s systems.”
By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don’t own.
CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.
Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.
This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.
Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.
The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.
After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.
“Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained.
“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”
CRLSets is a Chrome “emergency mechanism” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.
However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.
The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.
“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.
Google urges domain owners to:
- Monitor CT logs across their entire domain portfolio, including parked domains.
- Publish restrictive Certification Authority Authorization (CAA) records as needed to limit issuance to authorized ACME accounts and validation methods.
Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.
The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

