Hackers Hijack Google Domains After Breaching ccTLD Registries
Unauthorized HTTPS certificates issued; Ghana, American Samoa, and Sierra Leone domain redirection reported

Key Takeaways
- Unauthorized HTTPS certificates obtained for Google domains and ccTLDs in Ghana, American Samoa, and Sierra Leone.
- Attack involved compromise of third-party operators and modification of authoritative DNS records.
- Full scope of affected domains and exact exploitation methods remain under investigation.
- Google and affected registries are working on remediation.
Related Security News

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Google reported on October 6, 2026, that threat actors compromised the registry operations of three country-code top-level domains (.gh, .sl, and .as) and obtained unauthorized HTTPS certificates for several Google domains. Google confirmed its own infrastructure was not breached, but any domain ending in these ccTLDs was placed at risk of impersonation. With fraudulent certificates, attackers could execute man-in-the-middle or phishing attacks against end-users visiting affected domains.



