Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.
Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but “did not involve a compromise of Google’s systems.”
By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don’t own.
CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.
Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.
This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.
Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.
The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.
After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.
“Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained.
“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”
CRLSets is a Chrome “emergency mechanism” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.
However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.
The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.
“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.
Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.
The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Google warns of new Chrome zero-day bug exploited in attacks
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google halts open-source bug bounty program amid AI spam surge
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google fined €403 million over location data privacy violations
Engineer sentenced for locking over 3,000 devices on employer network
New Dell System Update flaw lets hackers gain root privileges
OpenAI will show visual ads in ChatGPT while you generate images
Free Identity Governance for up to 150 Users: Try Our Community Edition
73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.
Overdue a password health-check? Audit your Active Directory for free
Learn how to evaluate RMM security with eight practical tests. Find gaps before scaling endpoint management across customer environments.
Is your backup really out of reach? See what the latest attacks reveal.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



