Attackers hijack three country code domains to obtain unauthorized Google certificates
Hackers compromised infrastructure in three country-code domain registries to issue unauthorized HTTPS certificates for Google and other organizations.
FTMQ Security, written by our newsroom0 views

Cybercriminals compromised the infrastructure behind three country-code top-level domain namespaces, Malwarebytes Labs and Infosecurity Magazine reported on October 8. According to Google, hackers targeted the .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa registries to obtain unauthorized HTTPS certificates for Google domains and other organizations. The Register and The Hacker News also reported that attackers manipulated the internet addressing infrastructure to pass verification checks. [1][2][4][5]
Malwarebytes Labs reported that the incident was not a break in encryption and that internal Google systems were not breached. Instead, attackers manipulated domain name system addressing to pass validation checks required for certificates they did not legitimately control. Because these country-code domain endings are not limited to sites serving those specific regions, security researchers warn that the risk extends to users globally. [1]
As FTMQ Security reported earlier, attackers compromised the .gh, .sl, and .as registries to generate 12 unauthorized HTTPS certificates for Google and YouTube domains. Google confirmed on October 6 that its systems remained secure, and Chrome blocked the unauthorized certificates to protect user connections. [8]
In short
- Hackers compromised the .gh, .sl, and .as country-code top-level domain registries.
- Attackers obtained unauthorized HTTPS certificates for Google and other organizations.
- Google confirmed that its internal systems and encryption were not compromised.
- Chrome blocked the unauthorized certificates to protect user traffic.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Attackers hijack country-code domains to impersonate Google and other servicesMalwarebytes Labs, 2d ago (the report this story comes from)
- [2]Attackers hijacked top-level domains, minted fake security certs for Google and other orgsThe Register, 3d ago
- [3]Attackers hijack country-code domains to impersonate Google and other servicesMalwarebytes, 2d ago
- [4]Attackers Hijack Three ccTLDs to Obtain Google CertificatesInfosecurity Magazine, 2d ago
- [5]Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google DomainsThe Hacker News, 3d ago
- [6]Attackers Hijack 3 Country-code Registries, Obtain Google CertificatesSecurity Boulevard, 2d ago
Background
- [7]Attackers on Grokipedia
- [8]Attackers hijack top level domains to obtain unauthorized Google security certificates FTMQ Security, 3d ago
Our newsroom writes these reports with the help of software, from the 8 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
More in Cybercrime and Scams
- Anthropic launches free artificial intelligence security scanning service for open source maintainers1h ago
- Hackers breach ASOS systems and access customer search data1h ago
- High severity NVIDIA DCGM Exporter vulnerability threatens internet exposed GPU servers1d ago
- CISA adds actively exploited Citrix NetScaler zero day to KEV catalog5d ago
- Google freezes open source bug bounty program over invalid AI reports5d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.