Google reports hijacked ccTLDs used to mint fake TLS certificates for its domains
Google disclosed that attackers hijacked DNS infrastructure of three country-code top-level domains — .gh, .sl, and .as — and used that control to obtain unauthorized TLS certificates for several Google domains and other major brands. Google says it has updated Chrome to block the identified fraudulent certificates and worked with other certificate authorities to do the same across browsers.
GoKawiil's interpretation of the reporting above, not reported fact.
Because TLS certificates underpin trust between browsers and websites, counterfeit certificates could let attackers impersonate legitimate services, intercept traffic, or conduct phishing with valid-looking encryption. Google's admission that it cannot guarantee it has caught every fraudulent certificate suggests the exposure window may be wider than currently known, and its advice for domain owners to monitor certificate transparency logs implies the industry still relies heavily on after-the-fact detection rather than prevention.
- Attackers compromised DNS control of .gh, .sl, and .as ccTLDs to issue fraudulent TLS certificates.
- Google updated Chrome and coordinated with other certificate authorities to block known fake certificates.
- Google cannot confirm all fraudulent certificates have been found, urging domain owners to check transparency logs.
YubiKey 5 Series Security Key — This story is a reminder that domain and certificate infrastructure can be subverted, making phishing-resistant authentication more important than ever. A YubiKey adds hardware-backed, public-key-based login protection that doesn't rely solely on trusting a website's TLS certificate or DNS records, helping protect your accounts even if a service is targeted by this kind of attack.
See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: arstechnica.com, 2026-10-06
Published there as: “Hackers obtain counterfeit TLS certificates for Google and other large services”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.