According to a recent announcement by Google on October 6, attackers were able to compromise three country-code top-level domains (ccTLDs) and acquire unauthorized HTTPS certificates for various Google domains.
Although Google’s own systems remained unaffected, domains ending in .gh (Ghana), .sl (Sierra Leone), or .as (American Samoa) were potentially at risk. These unauthorized certificates could enable an attacker to impersonate a legitimate site over an encrypted connection and intercept sensitive data.
To combat this, Chrome promptly blocked the unauthorized certificates for Google’s domains using CRLSets, a mechanism designed to quickly revoke certificates in emergency situations. Additionally, Google collaborated with the certificate authorities (CAs) responsible for issuing the certificates to ensure they were revoked, safeguarding users of other browsers and applications.
While the specific domains were not disclosed, Certificate Transparency (CT) logs revealed the issuance of at least 12 certificates between September 22 and 27 for Google and YouTube domains under the three affected ccTLDs.
The attackers manipulated authoritative DNS records during the hijacking incidents, leading to the issuance of certificates. Google emphasized that the CAs acted in accordance with standard procedures, and there was no indication of misconduct on their part.
Key Findings from Certificate Logs
On October 7, The Hacker News identified the certificates issued for seven domains through CT search services. Notably, Let’s Encrypt issued 11 certificates, while ZeroSSL issued one.
The certificates were logged on separate days for each ccTLD: .gh on September 22, .sl on September 25, and .as on September 27.
All 12 certificates were domain-validated and issued following confirmation of domain ownership. Notably, previous records indicated that certificates for google.com.gh, google.sl, and google.as were primarily issued by Google Trust Services, Google’s internal CA.
In response to inquiries, a Let’s Encrypt representative confirmed the issuance and subsequent revocation of certificates for Google and YouTube domains.
While the focus was on Google’s domains, CT data suggested that other prominent organizations may have also been impacted by similar attacks. However, Google refrained from naming these entities.
Actions Taken and Recommendations
Following the discovery of the hijacks, Google promptly took measures to mitigate the threat. Chrome users were shielded from the unauthorized certificates, and affected organizations were notified wherever possible.
Domain owners were advised to monitor CT logs for all their domains, including regional ccTLDs, and implement strict CAA (Certificate Authority Authorization) records. Reporting any unauthorized certificates to the issuing CA was also encouraged as part of the industry’s Baseline Requirements.
While CAA records can’t prevent certificate issuance during a DNS hijack, they serve as a security measure once control is regained. By tying the record to their CA account, domain owners can prevent unauthorized certificate requests post-hijack.
Google also highlighted the evolving standards within the CA/Browser Forum, which dictate the duration for reusing domain checks. This shift aims to enhance certificate security and prevent future incidents of this nature.
Ensuring Certificate Security
Each certificate mentioned in the article can be verified using its SHA-256 fingerprint. By cross-referencing these fingerprints with CT search services, domain owners can confirm the certificates issued for their domains.
As the industry continues to refine security protocols, domain owners must remain vigilant and proactive in safeguarding their online assets against potential threats.




