> Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
[DATE: 07/10/2026 19:38]
[LANGUAGE: EN]
Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations. Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). “During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” Google security warned on Tuesday. Google did not say which specific domains or organizations were affected. The attacks did not compromise Google’s systems, and Chrome quickly blocked suspected counterfeit certificates across the affected ccTLDs - meaning Chrome browser users are already protected - according to the Chocolate Factory. “Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” the alert said. These types of attacks allow criminals to impersonate legitimate organizations and websites without triggering any browser security alerts. The attacker controls the traffic routing (via DNS) and the private key associated with the unauthorized certificate, which means they can potentially intercept or modify data sent by users to the impersonated site - and abuse the trusted organization's brand to distribute malware or conduct phishing attacks. “While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google warned domain owners. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” To ensure that their domains and users are protected, Google recommends ongoing monitoring of Certificate Transparency (CT) logs across all of an organization’s domains, including parked or regional ccTLD properties. This provides near real-time alerts whenever someone obtains a certificate for one of your domains. And if you operate a domain in .gh, .sl, or .as, definitely review recent CT log entries for unexpected certificates. Organizations can also publish restrictive Certification Authority Authorization (CAA) DNS records, which allow domain owners to specify which CAs are permitted to issue certificates for their domains. While this won’t stop certificates from being issued during a DNS hijacking attack, it helps safeguard domains after DNS control is restored. Google recommends CAA policies that restrict issuance to specific authorized accounts and validation methods and prevent attackers from using cached validation state to mint new certificates after a hijacking ends.®