The news
Attackers compromised third-party registries that run the country-code domains for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as), and obtained unauthorized HTTPS certificates for several Google domains and for sites of other organizations, Google said in a security blog post on October 6.
A country-code top-level domain, or ccTLD, is the national suffix at the end of a web address. The registry behind it holds the authoritative records that tell the internet where a domain such as google.com.gh actually lives. According to The Register, the attackers modified those authoritative DNS records, pointing the domains at infrastructure they controlled, and then obtained certificates for them.
That matters because an HTTPS certificate is what makes a browser show a site as genuine. With valid certificates in hand, attackers could impersonate legitimate organizations and websites without setting off browser security warnings, The Register reported. Google said the affected domains included several leading global brands and widely used online services, but it did not name them.
Google said Chrome immediately blocked the unauthorized certificates using CRLSets, its mechanism for pushing certificate block lists to the browser, and worked with the certificate authorities to revoke them. It also used Certificate Transparency logs, the public record of every certificate issued, to identify other affected organizations, blocked additional certificates in Chrome and contacted those companies.
Google did not blame the certificate authorities. A Google security statement quoted by The Register said it had no reason to believe the CAs that issued the certificates did anything wrong, given how the attacks worked. Google's own post said its analysis may not have caught every affected domain, and that Chrome's blocking does not reliably protect people using other browsers.
The numbers
- Country-code domains hijacked
- 3 (.gh, .sl, .as)
- Google disclosure
- October 6, 2026
Why CEOs should care
For CISOs and brand owners, this attack bypassed the company entirely. Nothing at Google had to be breached; the weak link was a registry operator in another country. Any company that holds country-code domains for local marketing, or defensively registers them to stop squatters, carries the same exposure. The first question to ask is simple: which ccTLDs do we hold, and who operates their registries?
Google's own advice is concrete. Monitor Certificate Transparency logs continuously across the whole domain portfolio, not only the main .com. Publish restrictive Certification Authority Authorization (CAA) records, DNS entries that limit which certificate authorities may issue for your domains, and bind them to specific ACME accounts, the automated issuance accounts most companies use. Review recent certificates for any .gh, .sl or .as domains you own.
For boards, the point is that browser vendors will not always catch this. Google warned that browser-side intervention should not be relied on to protect users. If customers reach a convincing fake site carrying your name and a valid padlock, the reputational and fraud costs land on you, not on the registry.
The bigger picture
The web's trust model assumes that whoever controls a domain's DNS is its rightful owner, and certificate authorities issue certificates on that basis. The incident shows that assumption breaks when the registry layer itself is compromised. Smaller national registries often run on third-party operators with fewer resources than the large commercial registries, which makes them an attractive point of attack for anyone trying to impersonate global brands.
What’s next
Google said it has contacted affected organizations. Domain owners should check Certificate Transparency logs for unexpected certificates on their country-code domains, add CAA records where missing, and watch for further disclosures from Google and the affected registries.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








