Google disclosed (6 October) that attackers compromised the third-party operators of the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) ccTLDs and modified authoritative DNS records, using that control to obtain unauthorised HTTPS certificates covering several Google domains as well as domains belonging to other organisations. Google stressed its own systems were not compromised, but has not said how the registries were hijacked, who is behind the attacks or when they began. Chrome immediately blocked the unauthorised certificates for Google properties via CRLSets — the browser's background-downloaded revocation list — and Google contacted affected organisations where it could; Chrome users need take no action. Every domain under the three endings was put at risk, though Google did not say all were hijacked. Registry/registrar compromise yielding trusted TLS certificates is a rare, high-impact interception primitive — worth checking whether any estate relies on .gh/.sl/.as domains.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-08 |
| Source | Help Net Security |
| Reliability | Tier 1 |