Google Domains Impacted by Recent ccTLD Hijacks
Description
Hackers hijacked the .gh, .sl, and .as country-code top-level domains (ccTLDs), modifying authoritative DNS records and obtaining unauthorized HTTPS certificates for several Google domains and other organizations. Google blocked these unauthorized certificates in Chrome and worked with certificate authorities to revoke them. The incident highlights risks associated with third-party ccTLD management and certificate issuance. Google recommends domain owners monitor Certificate Transparency logs and implement restrictive CAA DNS records to prevent future unauthorized certificate issuance.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Attackers compromised control over the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, enabling them to modify DNS records and obtain unauthorized HTTPS certificates for Google domains and others. Google identified the unauthorized certificates via Certificate Transparency logs, blocked them in Chrome, and collaborated with issuing certificate authorities to revoke them. The certificate authorities were not at fault due to the nature of the attack. Google advises domain owners to monitor CT logs and publish restrictive CAA DNS records to mitigate risks from cached domain control validation states after DNS control is restored.
Potential Impact
Unauthorized modification of DNS records for the affected ccTLDs allowed attackers to obtain fraudulent HTTPS certificates for Google domains and other organizations, potentially enabling man-in-the-middle or impersonation attacks. Google mitigated the risk by blocking the certificates in Chrome and revoking them with certificate authorities. However, some domains might still be affected if domain owners have not yet restored DNS control or implemented protective DNS policies. The incident affects all domains under the compromised ccTLDs (.gh, .sl, .as).
Defensive Guidance
Google has blocked the unauthorized certificates in Chrome and worked with certificate authorities to revoke them. Domain owners under the affected ccTLDs should monitor Certificate Transparency logs for unauthorized certificates and publish restrictive CAA DNS records to limit certificate issuance to authorized entities. Restoring restrictive CAA policies is critical to prevent attackers from exploiting cached domain control validation states after DNS control is regained. No further immediate action is required from end users, as Google has taken proactive steps to mitigate the threat.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/","fetched":true,"fetchedAt":"2026-10-09T11:48:23.439Z","wordCount":972}
Threat ID: 6ac8d4882cdf04f65650c260
Added to database: 10/09/2026, 11:48:24 UTC
Last enriched: 10/09/2026, 11:48:31 UTC
Last updated: 10/09/2026, 12:48:24 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.