Hackers hijack three country domains to mint counterfeit TLS certificates for Google

Hackers obtain counterfeit TLS certificates for Google and other large services

Hackers hijack three country domains to mint counterfeit TLS certificates for Google

Attackers seized control of the .gh, .sl, and .as country-code top-level domains, rewrote authoritative DNS records, and passed automated domain-control validation to obtain unauthorized TLS certificates for several Google domains and other major brands. Google updated Chrome to block the certificates it found and worked with the issuing certificate authorities to revoke them, but warned that browser-side fixes can't fully protect non-Chrome users or catch every affected domain.

While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users.

More from this day

2026-10-07