Google Says Attackers Hijacked Three Domain Registries and Got Certificates for Its Sites

Google said attackers who took over three countries' domain registries obtained unauthorized HTTPS certificates for web addresses they did not own, including several of Google's own. In a post published Oct. 6, 2026, its Chrome Secure Web and Networking Team said the hijacks hit the registries behind the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) domain endings, putting any address ending in those three at risk.
An HTTPS certificate is the file a browser checks to confirm that a website is the site it claims to be. One is issued only after the issuer verifies that the applicant controls the address, and that check reads the domain's DNS records, the entries that tell the rest of the internet where a site's traffic belongs. Google said the attackers changed those records at the compromised registries, that its own systems were not breached, and that it has no reason to believe the authorities that issued the certificates did anything wrong.
Google said Chrome used CRLSets, a built-in list of certificates the browser refuses, to block the certificates covering its own properties. It worked with the issuing authorities to have them revoked, so people using other software were covered too. Chrome users do not need to do anything to be protected, according to the Chrome team's post.
Google said that after its first round of blocking, public certificate logs turned up further organizations hit by the same attacks. Every certificate Chrome trusts has to be recorded in those logs, which the industry calls Certificate Transparency. Google described the newly found victims as well-known international brands and heavily used online services. It said Chrome blocked their certificates as well, alerting the organizations where it could.
Google does not say who carried out the hijacks.
The company told domain owners not to lean on the browser for protection, saying the complexity of such attacks means it cannot guarantee that its analysis found every affected address, and that blocking inside Chrome does not reliably protect people using other browsers. Google asked organizations to watch the public certificate logs for all of their addresses, including parked and regional ones, and to publish records naming which authorities are allowed to issue certificates for them.
