Skip to main content

Hackers hijack Google domains after breaching ccTLD registries

0
High
News
Published: 10/07/2026 (10/07/2026, 20:50:13 UTC)
Source: Bleeping Computer

Description

Hackers compromised third-party operators managing the authoritative DNS records for the country-code top-level domains (ccTLDs) of Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL). By modifying these DNS records, attackers were able to obtain unauthorized HTTPS certificates for several Google domains and other organizations' domains within these ccTLDs. This allowed them to hijack domains, redirect traffic to attacker-controlled infrastructure, and impersonate legitimate brands. Google confirmed its own systems were not compromised and worked with certificate authorities to revoke the fraudulent certificates and block them in Chrome. The incident highlights risks associated with third-party DNS registry security and certificate issuance processes.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 21:03:32 UTC

Technical Analysis

Threat actors breached third-party operators responsible for managing authoritative DNS records of the .GH, .AS, and .SL ccTLDs. By altering DNS records, they could request and obtain valid HTTPS certificates from certificate authorities for domains they did not own, including several Google domains and other organizations. This enabled domain hijacking and impersonation by redirecting visitors to attacker-controlled infrastructure. Google responded by blocking unauthorized certificates in Chrome using CRLSets, revoking certificates with CAs, and notifying affected organizations. The attack did not compromise Google's internal systems or indicate CA misbehavior. Google recommends monitoring Certificate Transparency logs and publishing restrictive CAA records to limit certificate issuance. The scope of affected domains may be larger than currently known, and protections are limited to Chrome users.

Potential Impact

The attackers gained control over DNS records for certain ccTLDs, enabling them to obtain legitimate HTTPS certificates for domains they did not own. This allowed them to hijack domains and impersonate legitimate websites, potentially deceiving users and serving arbitrary content. While Google's own systems were not compromised, the incident affected multiple organizations' domains within the targeted ccTLDs. The fraudulent certificates were blocked in Chrome, protecting Chrome users, but users of other browsers may remain vulnerable. The incident exposes risks in third-party DNS registry security and certificate issuance validation processes.

Defensive Guidance

Google has already revoked and blocked the unauthorized certificates in Chrome and worked with certificate authorities to revoke them. Chrome users are protected by these measures without needing to take action. Domain owners are urged to monitor Certificate Transparency logs for suspicious certificates and publish restrictive Certification Authority Authorization (CAA) DNS records to limit certificate issuance to authorized entities. However, CAA records cannot prevent certificate issuance during an active DNS hijack but help prevent further unauthorized certificates after DNS control is restored. Users of non-Chrome browsers may not be fully protected by these mitigations. Organizations should review their DNS registry security and certificate issuance monitoring practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/","fetched":true,"fetchedAt":"2026-10-07T21:03:23.999Z","wordCount":821}

Threat ID: 6ac6b39d2cdf04f6567ed28d

Added to database: 10/07/2026, 21:03:25 UTC

Last enriched: 10/07/2026, 21:03:32 UTC

Last updated: 10/07/2026, 21:03:32 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses