ccTLD Compromises Enable Issuance of Fake Google Domains Certificates
Attackers hijacked three country-code domains to trick certificate authorities into issuing valid HTTPS certificates for Google properties, bypassing standard validation checks.

Key points
- The .gh, .sl, and .as country-code top-level domains were compromised by threat actors.
- Valid HTTPS certificates for several Google domains were issued as a result of these hijacks.
- SecurityWeek reported that the incident highlights risks in domain validation processes for major services.
Threat actors successfully compromised three country-code top-level domains (ccTLDs) to obtain valid HTTPS certificates for multiple Google properties, according to a report by SecurityWeek. The incident involves the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) registries, which were hijacked to facilitate the issuance of fraudulent certificates that would appear legitimate to browsers and security tools.
Root cause
The underlying issue stems from the unauthorized control of the root zones for these specific ccTLDs. When an attacker gains administrative access to a ccTLD registry, they can create or modify domain records at will. This capability allows them to generate domains that appear to be subdomains or related to high-value targets like Google, thereby passing domain control validation checks used by certificate authorities during the issuance process.
Attack path
Attackers first seized control of the .gh, .sl, and .as registries. Once inside, they registered domains that mimicked Google’s domain structure. Using these compromised domains, they requested and received HTTPS certificates from public certificate authorities. These certificates are technically valid because the certificate authorities verified control over the requested domains, not the legitimacy of the underlying registry’s administrative integrity.
Affected versions
- Google Domains services were directly impacted by the issuance of fraudulent certificates.
- The .gh, .sl, and .as ccTLDs were the specific registries compromised in this campaign.
- No specific software version vulnerabilities were cited; the attack relied on registry-level access.
Mitigation
- Certificate authorities are expected to review validation logs for anomalies in high-risk ccTLDs.
- Google is likely revoking the improperly issued certificates to prevent their use in attacks.
- Registry operators must implement stricter administrative access controls to prevent future hijacks.
What to do and how to stay safe: Google
- Monitor certificate transparency logs for unexpected certificates issued for your organisation’s domains.
- Verify the administrative integrity of any ccTLDs your infrastructure relies upon for validation.
- Implement certificate pinning or strict validation policies for critical internal services.
- Review access controls for DNS management consoles to prevent unauthorised zone transfers.
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Which country-code domains were hijacked in this incident?
The .gh, .sl, and .as country-code top-level domains were compromised by attackers.
What did the attackers achieve with these hijacks?
They obtained valid HTTPS certificates for several Google domains, which could be used in phishing or interception attacks.
Is there a software patch for this vulnerability?
No specific software patch was mentioned; the issue relates to the security of the registry administration rather than a code defect.



