Hijacked Ghana Registry Exposed Google Domains to Fake Certificates

Google says attackers hijacked three country-code registries and obtained 12 unauthorised certificates for Google-related domains. All 12 identified certificates have been revoked, but the full impact remains unknown.

Google Domain Data bleech
AI Generated : Nano Banana

The short version

  • Attackers compromised the .gh, .sl and .as country-code registries and altered authoritative DNS records.
  • Certificate Transparency logs recorded 12 domain-validated certificates for seven domains.
  • Let's Encrypt issued 11 certificates and ZeroSSL issued one.
  • All 12 certificates were revoked, but revocation took from about a day and a half to nearly a week.
  • Google has not said whether any certificate was used to pose as a Google site or read users' data.

Why it matters: Any domain ending in .gh, .sl or .as was put at risk while the registries were compromised.

Google says attackers hijacked three country-code registries and certificates for Google domains, with all 12 identified certificates now revoked.

Google's systems were not breached, but domains using the Ghanaian, Sierra Leonean and American Samoan country-code registries were placed at risk. The number of affected domains and whether any certificate was used against users remain unknown.

Explainer

How the certificates were issued

The attackers compromised three third-party registry operators, modified authoritative DNS records and obtained unauthorised HTTPS certificates for several Google domains, Google said.

Between September 22 and 27, Certificate Transparency logs showed at least 12 certificates issued for Google and YouTube names across the three country-code domains. The names included google.com.gh, google.sl and google.as.

  • 12for seven domainsCertificates identified
  • 11one by ZeroSSLIssued by Let's Encrypt
  • 12all identified certificatesDomain-validated

Certificate Transparency records

All 12 were domain-validated certificates, meaning they were issued after a check that the applicant controlled the domain.

Country-code domainLoggedIssuing authorityRevocation
.ghSeptember 22Not specified for the two certificatesSeptember 26
.slSeptember 25Not specifiedOctober 1 for the other nine certificates
.asSeptember 27Not specifiedOctober 1 for the other nine certificates
All identified certificatesSeptember 22 to 27Let's Encrypt: 11; ZeroSSL: oneAll revoked by October 7

The reviewed records extend back to at least September 10. Google Trust Services, Google's own certificate authority, issued every other certificate for google.com.gh, google.sl and google.as.

  1. September 22.gh certificates recorded The first certificates in the sequence appeared under Ghana's country-code domain.
  2. September 25.sl certificates recorded The sequence moved to Sierra Leone's country-code domain.
  3. September 26Two .gh certificates revoked The ZeroSSL certificate was also revoked.
  4. September 27First .as certificate recorded The first American Samoa certificate appeared about a day after the .gh certificates were revoked.
  5. October 1Other nine certificates revoked The remaining certificates were revoked.
  6. October 7All 12 shown as revoked Cert Spotter's records showed all 12 certificates as revoked.

About a day and a half separated the first log entry from revocation for the certificate with the shortest interval. For the longest, the interval was nearly a week.

Response

Google's response and remaining exposure

Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks.

GoogleCompany

Google said the attacks affected domains of other organisations in the .GH, .SL and .AS country-code domains but did not involve a compromise of Google's systems.

To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.

GoogleCompany

Through CRLSets, Google's emergency method for quickly blocking certificates, Chrome blocked the certificates for Google's domains. Google coordinated with the issuing authorities on their revocation, which broadened protection to other clients.

Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.

GoogleCompany

CAA DNS records cannot prevent certificates from being issued during an active DNS hijack. Google said they can stop further certificates from being obtained through cached domain validation once legitimate DNS control has been restored. Under the CAA standard, an attacker could still obtain a certificate during a hijack by removing a CAA record or adding a false one.

Google said Chrome users do not need to take any action and that the company has not identified the attackers, said how many certificates were confirmed to have been hijacked, or explained how the three country-code registries were compromised.

Google's post leaves open whether any certificate was used to impersonate a Google site or access users' data. It provides no information on whether the registries have been secured, the dates of the hijacks or Google's own actions, or the names of the other affected organisations.

Sources and further reading

  1. Hackers hijack Google domains after breaching ccTLD registries — BleepingComputer , 2026-10-07
  2. Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains — The Hacker News , 2026-10-08

This article was prepared by the GlobePrism editorial team from the public reporting linked above. How we report

Frequently asked questions

Were Google's systems breached?

No. Google said the attacks did not involve a compromise of its systems.

Do Chrome users need to take action?

No. Google said Chrome users do not need to take any action, but users of other browsers might not be protected.

Were the certificates used against users?

Google has not said whether any certificate was used to pose as a Google site or read users' data.