Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Compromised country-code top-level domains enabled issuance of unauthorized HTTPS certificates for Google services

Key Takeaways
- Threat actors compromised the registry operations of three country-code top-level domains (.gh, .sl, .as) and obtained unauthorized HTTPS certificates for Google domains.
- Google confirmed its own infrastructure was not breached, but any domain ending in these TLDs was placed at risk of impersonation.
- Fraudulent certificates could enable man-in-the-middle or phishing attacks against end-users.
Related Security News

Hackers Hijack Google Domains After Breaching ccTLD Registries
Security researchers report that unaffiliated threat actors compromised third-party operators and modified authoritative DNS records to obtain unauthorized HTTPS certificates for several Google domains and hijack domains in the country-code top-level domains for Ghana, American Samoa, and Sierra Leone. The full scope and specific domains affected remain under investigation.




