By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Attackers Hijack ccTLDs for Google Domains HTTPS Certificates

Attackers successfully compromised three country-code top-level domains (ccTLDs) to obtain unauthorized HTTPS certificates for several Google domains, according to a statement from Google on October 6. The affected ccTLDs were .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). Google emphasized that its own internal systems were not breached during this incident. However, the compromise meant that any domain registered under these specific ccTLDs was put at risk of impersonation over encrypted connections.
With a valid HTTPS certificate, an attacker can impersonate a legitimate website, even over an encrypted connection, making it difficult for users to detect malicious activity. This type of attack, often referred to as a man-in-the-middle attack, can be used to steal sensitive information such as login credentials, financial data, or personal details. The ability to obtain certificates for Google domains suggests a sophisticated operation targeting the infrastructure that underpins secure web access for a significant number of users and businesses.
Google has stated it is working with the registry operators of the affected ccTLDs to revoke the unauthorized certificates and implement additional security measures. The company also indicated that it is reviewing its own processes for domain registration and certificate issuance to prevent similar incidents in the future. While Google's direct systems were not compromised, the incident highlights vulnerabilities in the broader domain name system (DNS) and certificate authority ecosystem. The compromise of ccTLDs, which are managed by national or regional authorities, can have far-reaching implications, especially when they are used by major service providers like Google.
The attack underscores the critical importance of robust security practices not only for individual organizations but also for the entities responsible for managing internet infrastructure. The incident serves as a reminder that even well-established companies with strong internal security can be indirectly affected by weaknesses in third-party systems. Google's proactive disclosure of the event and its ongoing remediation efforts aim to mitigate the impact on its users and restore trust in the security of its domain services. Further details on the specific methods used by the attackers and the extent of the compromise are expected to be released as investigations continue.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.