Hackers hijack domain registries to obtain counterfeit TLS certificates for Google and other services
Hackers hijacked three country-code top-level domain registries—specifically .gh, .sl, and .as—and modified their DNS records to pass automated domain control validation checks.

Hackers hijacked three country-code top-level domain registries—specifically .gh, .sl, and .as—and modified their DNS records to pass automated domain control validation checks. This allowed the attackers to obtain unauthorized, counterfeit TLS (Transport Layer Security) certificates for several Google domains and other major online services, as announced by Google on Tuesday.
TLS certificates use digital signatures to bind a domain name to a public key, giving attackers the power to cryptographically impersonate affected infrastructure. In response, Google updated its Chrome browser to block all identified unauthorized certificates and worked with issuing certification authorities to revoke the fraudulent Google credentials.
While all known unauthorized certificates have been blocked and the risk is mitigated, Google noted that the complexity of DNS hijacks means it cannot guarantee every affected domain was identified, and browser-side interventions do not reliably protect non-Chrome users.
WireUnWired turns the supplied report into a clearer brief, preserves the original publisher and author details, and adds relevant context without hiding where the information came from.
Relevant WireUnWired coverage is connected so one story can lead into the larger technology context.
Original publication: 7 October 2026 00:51



