Skip to content
See the World Through ScienceA project of ALLATRA

Google Says Attackers Hijacked Three Domain Registries and Got Certificates for Its Sites

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A long concrete data center building behind a security fence, with a wooden sign reading Google at the entrance path.
Google's data center campus at The Dalles, Oregon. The unauthorized certificates covered Google web addresses, while the systems the attackers broke into belonged to three national domain registries (illustrative)."Google data center" by Lambtron, via wikimedia, CC-BY-SA-4.0

Google said attackers who took over three countries' domain registries obtained unauthorized HTTPS certificates for web addresses they did not own, including several of Google's own. In a post published Oct. 6, 2026, its Chrome Secure Web and Networking Team said the hijacks hit the registries behind the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) domain endings, putting any address ending in those three at risk.

An HTTPS certificate is the file a browser checks to confirm that a website is the site it claims to be. One is issued only after the issuer verifies that the applicant controls the address, and that check reads the domain's DNS records, the entries that tell the rest of the internet where a site's traffic belongs. Google said the attackers changed those records at the compromised registries, that its own systems were not breached, and that it has no reason to believe the authorities that issued the certificates did anything wrong.

Google said Chrome used CRLSets, a built-in list of certificates the browser refuses, to block the certificates covering its own properties. It worked with the issuing authorities to have them revoked, so people using other software were covered too. Chrome users do not need to do anything to be protected, according to the Chrome team's post.

Google said that after its first round of blocking, public certificate logs turned up further organizations hit by the same attacks. Every certificate Chrome trusts has to be recorded in those logs, which the industry calls Certificate Transparency. Google described the newly found victims as well-known international brands and heavily used online services. It said Chrome blocked their certificates as well, alerting the organizations where it could.

Google does not say who carried out the hijacks.

The company told domain owners not to lean on the browser for protection, saying the complexity of such attacks means it cannot guarantee that its analysis found every affected address, and that blocking inside Chrome does not reliably protect people using other browsers. Google asked organizations to watch the public certificate logs for all of their addresses, including parked and regional ones, and to publish records naming which authorities are allowed to issue certificates for them.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Google Says Attackers Hijacked Three Domain Registries and Got Certificates for Its Sites

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.