Skip to main content

Google Domains Impacted by Recent ccTLD Hijacks

0
High
News
Published: 10/09/2026 (10/09/2026, 11:43:14 UTC)
Source: SecurityWeek

Description

Hackers hijacked the .gh, .sl, and .as country-code top-level domains (ccTLDs), modifying authoritative DNS records and obtaining unauthorized HTTPS certificates for several Google domains and other organizations. Google blocked these unauthorized certificates in Chrome and worked with certificate authorities to revoke them. The incident highlights risks associated with third-party ccTLD management and certificate issuance. Google recommends domain owners monitor Certificate Transparency logs and implement restrictive CAA DNS records to prevent future unauthorized certificate issuance.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 11:48:31 UTC

Technical Analysis

Attackers compromised control over the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, enabling them to modify DNS records and obtain unauthorized HTTPS certificates for Google domains and others. Google identified the unauthorized certificates via Certificate Transparency logs, blocked them in Chrome, and collaborated with issuing certificate authorities to revoke them. The certificate authorities were not at fault due to the nature of the attack. Google advises domain owners to monitor CT logs and publish restrictive CAA DNS records to mitigate risks from cached domain control validation states after DNS control is restored.

Potential Impact

Unauthorized modification of DNS records for the affected ccTLDs allowed attackers to obtain fraudulent HTTPS certificates for Google domains and other organizations, potentially enabling man-in-the-middle or impersonation attacks. Google mitigated the risk by blocking the certificates in Chrome and revoking them with certificate authorities. However, some domains might still be affected if domain owners have not yet restored DNS control or implemented protective DNS policies. The incident affects all domains under the compromised ccTLDs (.gh, .sl, .as).

Defensive Guidance

Google has blocked the unauthorized certificates in Chrome and worked with certificate authorities to revoke them. Domain owners under the affected ccTLDs should monitor Certificate Transparency logs for unauthorized certificates and publish restrictive CAA DNS records to limit certificate issuance to authorized entities. Restoring restrictive CAA policies is critical to prevent attackers from exploiting cached domain control validation states after DNS control is regained. No further immediate action is required from end users, as Google has taken proactive steps to mitigate the threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/","fetched":true,"fetchedAt":"2026-10-09T11:48:23.439Z","wordCount":972}

Threat ID: 6ac8d4882cdf04f65650c260

Added to database: 10/09/2026, 11:48:24 UTC

Last enriched: 10/09/2026, 11:48:31 UTC

Last updated: 10/09/2026, 12:48:24 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses