Attackers hijacked three country-code top-level domain registries and then used them to obtain unauthorized HTTPS certificates for Google and YouTube properties. Google disclosed the incident on October 6 and confirmed that its own systems suffered no breach.
The compromised registries belong to .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). By altering authoritative DNS records at these third-party registries, the attackers passed automated domain-control validation at certificate authorities. As a result, they obtained at least 12 certificates for Google and YouTube names across the affected domains. The Alphabet-owned company clarified:
During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations. Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong.
Of the 12 certificates, Let’s Encrypt issued 11 and ZeroSSL issued one. The attackers obtained all of them between September 22 and 27, targeting one country-code domain at a time. Importantly, Google said it has no reason to believe the certificate authorities acted improperly. Instead, the attackers exploited the registries rather than the CAs themselves.
In response, Google blocked the unauthorized certificates in Chrome using CRLSets and also worked with the CAs to revoke them. By October 7, Certificate Transparency search tools confirmed that CAs had revoked all 12. Furthermore, Google found that the hijacks also affected “several leading global brands and widely used online services.” It therefore proactively blocked those certificates too and contacted the affected organizations where possible.
With both DNS control and a valid certificate, an attacker can intercept or modify user traffic without triggering browser warnings. This makes the attack particularly dangerous for users outside Chrome, since Google’s CRLSet protections only cover its own browser. Consequently, Google cautioned that browser-side fixes alone cannot protect everyone.
For longer-term defense, Google said it is also pursuing shorter certificate validity periods and limits on domain validation reuse through its Chrome Root Program. In addition, the company recommended that all domain owners monitor Certificate Transparency logs across their full portfolio, including parked and regional domains. It also urged organizations to publish restrictive CAA DNS records tied to specific accounts and validation methods.
Anyone currently operating domains under .gh, .sl, or .as should therefore review recent CT entries for unexpected certificate activity.

















