ccTLD hijack minted fake certificates for Google
.gh, .sl and .as registries abused for trusted TLS certs

ccTLD hijack minted fake certificates for Google

Google said on 6 October 2026 that unknown attackers hijacked three country-code domain registries and used that control to obtain unauthorized HTTPS certificates. The registries are .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa. Google's own systems were not breached.

What happened

With control of the registries, the attackers changed authoritative DNS and passed normal domain-control checks at certificate authorities. Public Certificate Transparency records show at least 12 certificates for Google and YouTube names, including google.com.gh, youtube.com.gh, google.sl, google.com.sl, youtube.sl, google.as, and youtube.as. Let's Encrypt issued 11. ZeroSSL issued one. Issuance ran from 22 to 27 September, one registry at a time.

Google said the certificate authorities did not do anything wrong. The failure was registry and DNS control. Chrome blocked the unauthorized certificates through CRLSets. By 7 October the 12 Google and YouTube certificates had been revoked. Google also said several other leading brands and widely used services were caught in the same hijacks, and that it contacted those organisations. It did not name them.

Who is affected

  • Anyone relying on a name under .gh, .sl, or .as between 22 September and revocation in early October.
  • Users of other browsers before revocation, because Chrome's block does not protect every client.
  • Organisations that own a brand name on one of those three ccTLDs, even if the main site is on .com.

What to do now

Search Certificate Transparency for every name you own under .gh, .sl, and .as, and confirm with the registry operator that your nameserver delegation was not changed in late September. If you find a certificate you did not request, ask the issuer to revoke it and rotate any secret that could have been entered on the impostor site. Do not assume a Chrome block covers mobile apps or other browsers.

Source: Ars Technica, 6 October 2026. Hackers obtain counterfeit TLS certificates for Google and other large services.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

LMCache CVE-2026-105192 unauthenticated RCE, no patch
Pickle on the default ZMQ port in LMCache through 0.5.5