"During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations," Google security warned on Tuesday.
The hijacks in .gh, .sl and .as
Google said it became aware last week of a series of attacks that targeted three country-code top-level namespaces: .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). The company did not disclose which specific Google domains or which other organizations' domains were affected. Google also said the attacks did not compromise Google’s systems.
How attackers combined DNS control with fraudulent TLS certificates
According to Google, attackers changed authoritative DNS records for domains within those ccTLDs and obtained unauthorized HTTPS certificates for several Google domains and for domains belonging to other organizations. Because the attackers controlled DNS routing and held the private keys tied to the unauthorized certificates, they could impersonate legitimate sites without triggering browser security warnings. Google warned this combination "allows criminals to impersonate legitimate organizations and websites" and to intercept or modify data sent by users, or to use the trusted brands to distribute malware or run phishing campaigns.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildChrome's intervention and Google's assessment of certificate authorities
Google said Chrome "quickly blocked suspected counterfeit certificates across the affected ccTLDs," and added that Chrome browser users are already protected. Still, Google cautioned that browser-side measures are not a comprehensive defense: "browser-side intervention should not be relied on to protect your users," and Chrome interventions "do not reliably protect non-Chrome users." Google also stated that, "Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong."
Google's defensive recommendations for domain operators
To reduce future risk, Google recommended continuous monitoring of Certificate Transparency (CT) logs across all of an organization's domains — including parked names and regional ccTLD properties — to receive near-real-time alerts when any certificate is issued for a domain. For operators of domains in .gh, .sl and .as, Google specifically urged reviewing recent CT log entries for unexpected certificates.
Google also suggested publishing restrictive Certification Authority Authorization (CAA) DNS records, which let domain owners specify which CAs are allowed to issue certificates for their domains. While CAA records "won’t stop certificates from being issued during a DNS hijacking attack," the company said they "help safeguard domains after DNS control is restored." Google recommends CAA policies that restrict issuance to specific authorized accounts and validation methods and that prevent attackers from using cached validation state to mint new certificates after a hijacking ends.
What this means for domain owners, Certificate Authorities, and end users
- Domain owners: Operators with properties in .gh, .sl and .as should review recent Certificate Transparency logs for unexpected issuance, adopt restrictive CAA records, and treat browser-blocking as an emergency mitigation rather than a full cure.
- Certificate Authorities (CAs): Google expressed no reason to blame issuing CAs in these incidents, but the events underline the value of coordination with domain owners and real-time CT visibility to detect and mitigate unauthorized issuance quickly.
- End users: Chrome users saw suspected counterfeit certificates blocked quickly; Google warned, however, that protections vary by browser and that Chrome interventions "do not reliably protect non-Chrome users."
The incidents in .gh, .sl and .as underline a simple but consequential truth: control of DNS can be as powerful as control of servers. Google’s public guidance focuses on detection (CT logs) and post-incident hardening (CAA policies and restricted validation) rather than assigning blame for issuance. For domain operators and certificate issuers alike, the next practical steps are clear — tighten who can obtain certificates for your names, watch CT logs continuously, and assume browser blocking will not shield every user.




