Google said it became aware last week of attacks in the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level namespaces. During the hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations, Google security warned in a blog post on Tuesday. Google did not name the specific domains or organizations affected.
The attack is dangerous precisely because it is invisible to users. Controlling the traffic routing via DNS and the private key of an unauthorized certificate lets criminals impersonate legitimate organizations without triggering browser security alerts, and potentially intercept or modify user data or distribute malware under a trusted brand. Google said its own systems were not compromised and that the certification authorities “did nothing wrong.”
Chrome blocked suspected counterfeit certificates across the affected ccTLDs, so Chrome users are protected, but Google warned that browser-side intervention “should not be relied on” because it cannot guarantee every affected domain was identified and it does not protect non-Chrome users. Google recommends domain owners monitor Certificate Transparency logs across all domains, including parked and regional ccTLD properties, and publish CAA records restricting which certificate authorities can issue for their domains.