Google Domains and ccTLDs Hijacked via DNS Record Compromise
Hackers gained control over DNS records for Google domains and ccTLDs in Ghana, American Samoa, and Sierra Leone by infiltrating third-party registries. They obtained valid HTTPS certificates for these domains, enabling impersonation and malicious content delivery. Google responded by revoking the certificates and working with authorities to prevent further misuse, affirming that its own systems remained unaffected.
GoKawiil's interpretation of the reporting above, not reported fact.
This incident highlights vulnerabilities in domain registration processes and the risks posed by third-party registries. It suggests that attackers can exploit DNS record access to impersonate brands and compromise online trust, prompting a need for enhanced security measures across domain management systems. The event underscores the importance of vigilant monitoring and rapid response to protect digital infrastructure and user safety.
- Domain registration security is critical to prevent hijacking.
- Third-party registry vulnerabilities can impact major brands.
- Proactive certificate revocation is essential for mitigating attacks.
Source: bleepingcomputer.com, 2026-10-07
Published there as: “Hackers hijack Google domains after breaching ccTLD registries”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.