# Cyber Attackers Breach ccTLDs to Forge Google Domain Certificates

*Published October 9, 2026*
*Source: [https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html](https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/cyber-attackers-breach-cctlds-to-forge-google-domain-certificates) or [see plans](https://www.sec-news.ai/pricing).*

## Article

In a recent cyberattack, hackers compromised three country-code top-level domains (ccTLDs) to secure unauthorized HTTPS certificates for several Google domains. The affected ccTLDs were .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa. Although Google's internal systems remained secure, the unauthorized certificates allowed attackers to potentially impersonate legitimate sites and intercept private data. Google acted swiftly by blocking these certificates in Chrome using CRLSets and collaborated with certificate authorities (CAs) to revoke them, protecting users across various browsers and applications.

Certificate Transparency logs revealed that between September 22 and 27, at least 12 certificates were issued for domains such as google.com.gh, google.sl, and google.as. These certificates were domain-validated, indicating that the attackers manipulated authoritative DNS records during the hijacking process. Google confirmed that neither their systems nor the CAs were at fault.

The unauthorized certificates were discovered by The Hacker News using CT search services. Let's Encrypt issued 11 of these certificates, while ZeroSSL issued one. All certificates were revoked by October 7, with the revocation process beginning on September 26. Despite the swift revocation, Google's analysis suggests other organizations might have been targeted, although specific names were not disclosed.

Google's response included blocking the compromised certificates in Chrome and notifying affected organizations. However, they cautioned domain owners against relying solely on browser protections, as DNS hijacking complexity means some affected domains might not be identified. Google recommended domain owners implement strict CAA records to prevent future unauthorized certificate issuance. The company did not disclose details about how the ccTLDs were compromised or identify the attackers.
