Real Certificates For Fake Sites, Without Touching A CA
On 6 October 2026 Google disclosed that attackers had compromised the registries of three country-code top-level domains: .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. By changing authoritative DNS records, they obtained unauthorized HTTPS certificates covering several Google domains and domains belonging to other organizations.
Google's own systems were not breached, and it has no reason to believe the certificate authorities that issued the certificates did anything wrong. That is what makes the attack instructive. A certificate authority issues a certificate once the applicant proves control of the domain, often by publishing a record in its DNS. Whoever controls the DNS passes that test honestly.
An attacker holding the certificate, its private key and the DNS can impersonate the real site over a connection the browser shows as secure, with no warning at all.
What The Public Logs Show
The Hacker News searched Certificate Transparency logs on 7 October, and the records give a timeline Google did not publish.
| Country-code domain | Territory | First certificate logged |
|---|---|---|
| .gh | Ghana | 22 September |
| .sl | Sierra Leone | 25 September |
| .as | American Samoa | 27 September |
It found at least 12 certificates covering seven domains, all domain-validated: Let's Encrypt issued 11 and ZeroSSL one. In records going back to at least 10 September, every other certificate for google.com.gh, google.sl and google.as came from Google Trust Services, Google's own authority. A Let's Encrypt staff member confirmed on the community forum on 7 October that certificates for Google and YouTube were issued and have been revoked.
Revocation was not instant. Two .gh certificates and the ZeroSSL certificate were revoked on 26 September and the other nine on 1 October, so the gap between first log entry and revocation ran from about a day and a half to nearly a week. The check covered only a small set of Google and YouTube names, so the true total may be higher.
Why Browser Protection Is Not Your Protection
Chrome blocked the certificates it found through CRLSets, its emergency list for revoked or untrusted certificates, and Chrome users need to do nothing. Google was explicit about the limit: it cannot guarantee it found every affected domain, and its interventions do not reliably protect people using other browsers.
Certificate Transparency showed Google other organizations hit by the same attacks, including several leading global brands and widely used online services, and it contacted those it could. Google did not name them. If your company holds a regional or parked domain under a small country-code registry, you cannot assume someone told you.
The registry is the part nobody on your side controls. Your DNS provider, your registrar account and your multi-factor login do not help when the operator of the whole top-level domain is compromised.
What To Do This Week
List every domain your organisation holds, including parked and regional country-code names, and note the registry behind each. Subscribe to a Certificate Transparency monitor for all of them, because CT is the only independent alert that fires when someone obtains a certificate in your name.
Publish restrictive CAA records that name the certificate authorities you use and bind issuance to your own ACME account and validation method. Google says CAA cannot stop issuance during an active hijack, but it stops an attacker from reusing a cached validation to mint new certificates after you regain control.
If you hold anything under .gh, .sl or .as, review recent log entries for certificates you did not request. For everything else, put one named person in charge of a simple question: who gets the alert when an unknown certificate appears?
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: The Best AI Hacking Tools Are Now Invitation-Only | Chrome's Next Zero-Day Files to Brussels



