Google says attackers hijacked three country-code registries and certificates for Google domains, with all 12 identified certificates now revoked.
Google's systems were not breached, but domains using the Ghanaian, Sierra Leonean and American Samoan country-code registries were placed at risk. The number of affected domains and whether any certificate was used against users remain unknown.
How the certificates were issued
The attackers compromised three third-party registry operators, modified authoritative DNS records and obtained unauthorised HTTPS certificates for several Google domains, Google said.
Between September 22 and 27, Certificate Transparency logs showed at least 12 certificates issued for Google and YouTube names across the three country-code domains. The names included google.com.gh, google.sl and google.as.
All 12 were domain-validated certificates, meaning they were issued after a check that the applicant controlled the domain.
| Country-code domain | Logged | Issuing authority | Revocation |
|---|---|---|---|
| .gh | September 22 | Not specified for the two certificates | September 26 |
| .sl | September 25 | Not specified | October 1 for the other nine certificates |
| .as | September 27 | Not specified | October 1 for the other nine certificates |
| All identified certificates | September 22 to 27 | Let's Encrypt: 11; ZeroSSL: one | All revoked by October 7 |
The reviewed records extend back to at least September 10. Google Trust Services, Google's own certificate authority, issued every other certificate for google.com.gh, google.sl and google.as.
- September 22.gh certificates recorded The first certificates in the sequence appeared under Ghana's country-code domain.
- September 25.sl certificates recorded The sequence moved to Sierra Leone's country-code domain.
- September 26Two .gh certificates revoked The ZeroSSL certificate was also revoked.
- September 27First .as certificate recorded The first American Samoa certificate appeared about a day after the .gh certificates were revoked.
- October 1Other nine certificates revoked The remaining certificates were revoked.
- October 7All 12 shown as revoked Cert Spotter's records showed all 12 certificates as revoked.
About a day and a half separated the first log entry from revocation for the certificate with the shortest interval. For the longest, the interval was nearly a week.
Google's response and remaining exposure
Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks.
Google said the attacks affected domains of other organisations in the .GH, .SL and .AS country-code domains but did not involve a compromise of Google's systems.
To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.
Through CRLSets, Google's emergency method for quickly blocking certificates, Chrome blocked the certificates for Google's domains. Google coordinated with the issuing authorities on their revocation, which broadened protection to other clients.
Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.
CAA DNS records cannot prevent certificates from being issued during an active DNS hijack. Google said they can stop further certificates from being obtained through cached domain validation once legitimate DNS control has been restored. Under the CAA standard, an attacker could still obtain a certificate during a hijack by removing a CAA record or adding a false one.
Google said Chrome users do not need to take any action and that the company has not identified the attackers, said how many certificates were confirmed to have been hijacked, or explained how the three country-code registries were compromised.
Google's post leaves open whether any certificate was used to impersonate a Google site or access users' data. It provides no information on whether the registries have been secured, the dates of the hijacks or Google's own actions, or the names of the other affected organisations.

