Attackers breached three country-code top-level domain (ccTLD) registries and obtained unauthorized HTTPS certificates for several Google domains, Google announced on Oct. 6. Google’s systems were not compromised, but any domain ending in .gh (Ghana), .sl (Sierra Leone), or .as (American Samoa) was compromised. With such a certificate, an attacker could impersonate the real website over an encrypted connection and read private data sent to it.
See also: Google's AI detector SynthID is now available to everyone

Chrome blocked the unauthorized certificates for Google domains via CRLSets, its way of quickly blocking certificates in emergency situations. The company also worked with the certificate authorities (CAs) that issued the certificates to revoke them, a step intended to protect users of other browsers and apps. Google did not name the domains. The Certificate Transparency (CT) files are the public record of certificates issued by CAs. They show at least 12 certificates issued between September 22 and 27 for Google and YouTube names under three ccTLDs, including google.com.gh, google.sl and google.as.
A CA issues a certificate once the applicant has demonstrated control over the domain, for example by adding a record to the domain’s DNS. The attackers changed the authoritative DNS records during the takeovers, and Google has no reason to believe the CAs did anything wrong. Hacker News found the certificates on October 7 through two CT search services, ctlogs.dev and Cert Spotter.
The 12 certificates are for seven domains. Let's Encrypt issued 11 of them and ZeroSSL issued one. The certificates were listed on the records over three days, one ccTLD at a time: .gh on September 22, .sl on September 25, and .as on September 27. All 12 are domain-validated certificates, issued after verification that the applicant controls the domain. In the records reviewed, which date back at least to September 10, every other certificate for google.com.gh, google.sl, and google.as came from Google Trust Services, Google's own CA.
“ Yes, certificates were issued for Google and YouTube, and they have been revoked ,” Matthew McPherrin , a Let's Encrypt staff member , wrote on the CA community forum on October 7, responding to a user who asked if Let's Encrypt certificates were issued during the takeovers. Only a small set of Google and YouTube names were investigated, so the total number may be higher.
See also: Google's Pixel Buds update brings sleep tracking

Google said the CT data also pointed to other organizations it believes were affected by the same attacks, including well-known global brands and widely used online services. It did not name them. As of Oct. 7, Cert Spotter records showed all 12 certificates as revoked. The two .gh certificates and the ZeroSSL certificate were revoked on Sept. 26, and the other nine on Oct. 1.
The shortest gap between the first registration of a certificate and its revocation was about a day and a half. The longest was almost a week. The first .as certificate was registered on September 27, about a day after the .gh certificates were revoked.
Google said it learned of the takeovers the week before its Oct. 6 post and acted promptly. It did not give dates for the takeovers or its own actions. Google also blocked certificates it found for other organizations in Chrome, and contacted them where it could. Chrome users do not need to do anything, Google said. Domain owners should not rely on the browser to protect their users.
Because DNS hijackings are complex, “we cannot guarantee that our analysis identified every affected domain,” Chrome’s Safe Web and Networking Team wrote, adding that Chrome’s blocking does not reliably protect users of other browsers. Google’s post does not say whether any of the certificates were used to impersonate a Google site or read user data.
See also: Lawsuits against Google over AI Overviews dismissed

It did not name the attackers, say how the ccTLDs were breached, or whether they have been secured.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
