Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Google says hijacked .gh, .sl and .as registries let attackers get HTTPS certificates for its domains

Google says attackers compromised third-party operators of Ghana, Sierra Leone and American Samoa domains, changed DNS records and obtained valid certificates for its sites and others.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Attackers compromised registries for .gh, .sl and .as and obtained unauthorized HTTPS certificates for Google and other brands, Google said.
  • 2Chrome blocked the certificates, but Google warned browser protection should not be relied on and may not cover other browsers.
  • 3Google urges domain owners to monitor Certificate Transparency logs and publish restrictive CAA records.

The news

Attackers compromised third-party registries that run the country-code domains for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as), and obtained unauthorized HTTPS certificates for several Google domains and for sites of other organizations, Google said in a security blog post on October 6.

A country-code top-level domain, or ccTLD, is the national suffix at the end of a web address. The registry behind it holds the authoritative records that tell the internet where a domain such as google.com.gh actually lives. According to The Register, the attackers modified those authoritative DNS records, pointing the domains at infrastructure they controlled, and then obtained certificates for them.

That matters because an HTTPS certificate is what makes a browser show a site as genuine. With valid certificates in hand, attackers could impersonate legitimate organizations and websites without setting off browser security warnings, The Register reported. Google said the affected domains included several leading global brands and widely used online services, but it did not name them.

Google said Chrome immediately blocked the unauthorized certificates using CRLSets, its mechanism for pushing certificate block lists to the browser, and worked with the certificate authorities to revoke them. It also used Certificate Transparency logs, the public record of every certificate issued, to identify other affected organizations, blocked additional certificates in Chrome and contacted those companies.

Google did not blame the certificate authorities. A Google security statement quoted by The Register said it had no reason to believe the CAs that issued the certificates did anything wrong, given how the attacks worked. Google's own post said its analysis may not have caught every affected domain, and that Chrome's blocking does not reliably protect people using other browsers.

The numbers

Country-code domains hijacked
3 (.gh, .sl, .as)
Google disclosure
October 6, 2026

Why CEOs should care

For CISOs and brand owners, this attack bypassed the company entirely. Nothing at Google had to be breached; the weak link was a registry operator in another country. Any company that holds country-code domains for local marketing, or defensively registers them to stop squatters, carries the same exposure. The first question to ask is simple: which ccTLDs do we hold, and who operates their registries?

Google's own advice is concrete. Monitor Certificate Transparency logs continuously across the whole domain portfolio, not only the main .com. Publish restrictive Certification Authority Authorization (CAA) records, DNS entries that limit which certificate authorities may issue for your domains, and bind them to specific ACME accounts, the automated issuance accounts most companies use. Review recent certificates for any .gh, .sl or .as domains you own.

For boards, the point is that browser vendors will not always catch this. Google warned that browser-side intervention should not be relied on to protect users. If customers reach a convincing fake site carrying your name and a valid padlock, the reputational and fraud costs land on you, not on the registry.

The bigger picture

The web's trust model assumes that whoever controls a domain's DNS is its rightful owner, and certificate authorities issue certificates on that basis. The incident shows that assumption breaks when the registry layer itself is compromised. Smaller national registries often run on third-party operators with fewer resources than the large commercial registries, which makes them an attractive point of attack for anyone trying to impersonate global brands.

What’s next

Google said it has contacted affected organizations. Domain owners should check Certificate Transparency logs for unexpected certificates on their country-code domains, add CAA records where missing, and watch for further disclosures from Google and the affected registries.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

GoogleChromeDNS securityTLS certificatesccTLD

Earlier coverage of Google

All Google coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.