Attackers hijack top level domains to obtain unauthorized Google security certificates
Attackers compromised three country-code top-level domain registries and generated 12 unauthorized HTTPS certificates for Google and YouTube domains.
FTMQ Security, written by our newsroom0 views

Attackers compromised three country-code top-level domains and obtained unauthorized HTTPS certificates for several Google domains, according to The Hacker News, The Register, Gadget Review, news.lavx.hu, and CyberSecurityNews. Google said on October 6 that its own systems were not breached. However, any domain ending in .gh for Ghana, .sl for Sierra Leone, or .as for American Samoa was put at risk by the incident. [1][2][3][4][5]
The Hacker News reported that attackers obtained 12 unauthorized certificates for Google and YouTube domains after hijacking the .gh, .sl, and .as registries. A certificate authority acts as a trusted third party that stores, signs, and issues digital certificates to certify the ownership of a public key. With an unauthorized certificate, an attacker could pose as the genuine site over an encrypted connection and read private data sent to it. [1][7]
Google Domains operated as a domain name registrar and domain management service from 2014 until most of its assets were acquired by Squarespace on September 7, 2023. Following the breach, Google confirmed that its internal infrastructure remained secure, and Chrome acted to block the unauthorized certificates. [1][8]
In short
- Attackers compromised the .gh, .sl, and .as country-code top-level registries.
- Google said on October 6 that its internal systems were not breached.
- Attackers obtained 12 unauthorized certificates for Google and YouTube domains.
- Chrome blocked the unauthorized certificates to protect user connections.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google DomainsThe Hacker News, 6h ago (the report this story comes from)
- [2]Attackers hijacked top-level domains, minted fake security certs for Google and other orgsThe Register, 5h ago
- [3]Hackers Obtain Unauthorized TLS Certificates for Google via Hijacked DomainsGadget Review, 8h ago
- [4]Attackers Hijack Three Country-Code Registries to Obtain Unauthorized Google Certificatesnews.lavx.hu, 4h ago
- [5]Hackers Hijack .gh, .sl and .as Registry to Obtain Unauthorized HTTPS CertificatesCyberSecurityNews, 9h ago
Background
- [6]Hijackers in the September 11 attacks on Wikipedia
- [7]Certificate authority on Wikipedia
- [8]Google Domains on Wikipedia
Our newsroom writes these reports with the help of software, from the 8 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
More in Top Stories
- Discord security bot Double Counter breached exposing user email addresses1h ago
- FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators1h ago
- MonsterCloud owner charged over secret ransomware payments1h ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records1h ago
- FBI removes Accenture contractor following Oracle PeopleSoft data breach1d ago
- Fake AI Ad Portals Steal User Credentials and MFA Codes1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.