Attackers compromised the .gh, .sl and .as country-code registries, rewrote authoritative DNS and obtained valid HTTPS certificates for Google and YouTube names
Registry-level DNS hijacks of .gh, .sl and .as produced valid HTTPS certificates for Google names
Analysis
Google's Chrome Secure Web and Networking Team says attackers compromised the third-party .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level domains, modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains and domains of other organizations (Google, 2026-10-06). A certificate authority issues a domain-validated certificate once the applicant shows control of the domain, for example by adding a record to its DNS, so control of the registry's DNS passes that check; Google has no reason to believe the issuing authorities did anything wrong (The Hacker News, 2026-10-08; Google, 2026-10-06). Chrome blocked the Google certificates through its CRLSets mechanism and Google had the authorities revoke them; Certificate Transparency data then surfaced further organizations, among them leading global brands, whose certificates Chrome also blocked (Google, 2026-10-06).
The Hacker News' own review of public logs found 12 certificates for seven Google and YouTube names, 11 issued by Let's Encrypt and one by ZeroSSL, first logged on 2026-09-22 (.gh), 2026-09-25 (.sl) and 2026-09-27 (.as) and revoked between 2026-09-26 and 2026-10-01 (The Hacker News, 2026-10-08), and a Let's Encrypt staff member confirmed that certificates for Google and YouTube were issued and revoked (Let's Encrypt community forum, 2026-10-07). Google's post does not name the attackers, say how the registries were compromised, or say whether any certificate was used to pose as a Google site or read users' data (The Hacker News, 2026-10-08), and it names only these three registries (Google, 2026-10-06).
Triage: a valid, correctly chained certificate is no longer evidence that a site is genuine once registry DNS can be changed. In the logs The Hacker News reviewed, every other certificate for google.com.gh, google.sl and google.as came from Google's own authority, while the 12 unauthorized ones came from Let's Encrypt and ZeroSSL, so an issuing authority or account outside your inventory, especially several certificates for one registry's names logged within hours, is the discriminator (The Hacker News, 2026-10-08).
Cited evidence
During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations.
we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.
The 12 certificates are for seven domains. Let's Encrypt issued 11 of them and ZeroSSL issued one.
Yes, certificates for Google and Youtube were issued, and have been revoked.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.