Google said on 6 October 2026 that unknown attackers hijacked three country-code domain registries and used that control to obtain unauthorized HTTPS certificates. The registries are .gh for Ghana, .sl for Sierra Leone, and .as for American Samoa. Google's own systems were not breached.
What happened
With control of the registries, the attackers changed authoritative DNS and passed normal domain-control checks at certificate authorities. Public Certificate Transparency records show at least 12 certificates for Google and YouTube names, including google.com.gh, youtube.com.gh, google.sl, google.com.sl, youtube.sl, google.as, and youtube.as. Let's Encrypt issued 11. ZeroSSL issued one. Issuance ran from 22 to 27 September, one registry at a time.
Google said the certificate authorities did not do anything wrong. The failure was registry and DNS control. Chrome blocked the unauthorized certificates through CRLSets. By 7 October the 12 Google and YouTube certificates had been revoked. Google also said several other leading brands and widely used services were caught in the same hijacks, and that it contacted those organisations. It did not name them.
Who is affected
- Anyone relying on a name under .gh, .sl, or .as between 22 September and revocation in early October.
- Users of other browsers before revocation, because Chrome's block does not protect every client.
- Organisations that own a brand name on one of those three ccTLDs, even if the main site is on .com.
What to do now
Search Certificate Transparency for every name you own under .gh, .sl, and .as, and confirm with the registry operator that your nameserver delegation was not changed in late September. If you find a certificate you did not request, ask the issuer to revoke it and rotate any secret that could have been entered on the impostor site. Do not assume a Chrome block covers mobile apps or other browsers.
Source: Ars Technica, 6 October 2026. Hackers obtain counterfeit TLS certificates for Google and other large services.
Also on the blog
- SonicWall SMA1000 CVE-2026-102255 is CVSS 10
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 Fortinet device credentials still in play
- LMCache CVE-2026-105192 unauthenticated RCE, no patch
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.