Cybercrime

Google Domains Impacted by Recent ccTLD Hijacks

Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains.

DNS domain hijack

Google has disclosed that several of its domains were affected by a recent hijack of third-party country-code top-level domains (ccTLDs).

The incident occurred last week and targeted the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, putting all domains with those suffixes at risk.

“During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” the internet giant says.

According to Google, the Certification Authorities (CAs) that issued the certificates are not to be blamed, given the nature of the attacks.

Immediately after learning of the incident, Google blocked the unauthorized certificates for its domains in Chrome and worked with the issuing CAs to revoke them.

Analysis of Certificate Transparency (CT) log data revealed that multiple other organizations, including global brands and popular online services, have been affected.

Advertisement. Scroll to continue reading.

“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome. Where possible, we reached out to impacted organizations to alert them to our findings and actions,” Google says.

The internet giant notes that, while it took steps to identify and block the unauthorized certificates, certain domains might still be affected.

Google encourages domain owners to monitor CT logs for all their domains, especially for those in .gh, .sl, or .as, and to publish restrictive CAA DNS records to ensure safeguards after DNS control has been restored.

“Because CAs are permitted to cache and reuse completed domain control validation (DCV) checks for subsequent issuance, restoring a restrictive CAA policy, especially one that restricts issuance to specific authorized accounts and validation methods, prevents an attacker from using cached validation state to mint new certificates after a hijack ends,” Google notes.

Related: Chrome 155 Update Patches 247 Vulnerabilities

Related: Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Related: Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Related Content

Artificial Intelligence

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Artificial Intelligence

The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.

Artificial Intelligence

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Privacy & Compliance

Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data.

Artificial Intelligence

Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.

Artificial Intelligence

Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.

Data Protection

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.

Identity & Access

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version