Three Country-Code Domains Exploited to Issue Fraudulent Google Certificates
DNS hijacking across .gh, .sl, and .as namespaces enabled attackers to bypass validation checks and obtain unauthorised TLS credentials for major platforms.
Control of the Namespace
On 6 October 2026, Google disclosed that attackers had successfully compromised the administrative infrastructure of three country-code top-level domains: .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). The intrusions allowed adversaries to modify authoritative DNS records for selected domains within those namespaces, a capability they then leveraged to obtain fraudulent TLS certificates for Google properties and several other widely used online services.
The attack represents a materialisation of a threat scenario that certificate authorities and browser vendors have long anticipated but rarely seen executed at scale. By controlling the DNS layer at the ccTLD level, the attackers were able to answer domain validation challenges from certificate issuers, effectively proving temporary control over domains they did not legitimately own.
The Validation Bypass
TLS certificates serve as the cryptographic credentials that bind a domain name to a public key, enabling encrypted connections and authentication across the web. Certificate authorities issue these credentials only after verifying that the requester controls the domain in question. The standard verification methods include responding to DNS queries, hosting specific files at known URLs, or receiving email at designated addresses tied to the domain.
In this campaign, the attackers exploited their elevated DNS privileges to intercept and respond to automated validation checks. Once they modified the authoritative records for target domains, they could direct certificate authority queries to infrastructure under their control. The certificate authorities, following their standard protocols, issued valid certificates based on what appeared to be legitimate proof of domain ownership.
Google did not disclose the specific certificate authorities that issued the unauthorised credentials, nor did it reveal the full list of affected domains beyond noting that "several Google domains" and "several leading global brands" were targeted. The company confirmed that it identified the fraudulent certificates and pushed an update to Chrome to block them, while working with the issuing authorities to ensure formal revocation.
Weak Points in the Trust Model
The incident underscores structural vulnerabilities in the certificate issuance ecosystem. Certificate authorities operate under a trust model that assumes DNS infrastructure, particularly at the top-level domain layer, remains secure. When that assumption breaks, the entire validation chain collapses.
Country-code top-level domains present a particular risk surface. Unlike generic TLDs such as .com or .org, which are managed by large commercial entities with substantial security resources, many ccTLDs are operated by national telecommunications agencies or academic institutions with varying levels of operational maturity. Ghana's .gh registry is managed by the Network Computer Systems division of the University of Ghana; Sierra Leone's .sl has historically been administered through a combination of government and private-sector arrangements; American Samoa's .as is managed by AS Domain Registry, a commercial operator.
At Opentechwire, we've tracked certificate authority compromises and DNS hijacking incidents across emerging markets for the past three years. This particular attack is notable not for the technique, which is well understood, but for the breadth of the target set and the attacker's ability to compromise multiple ccTLD operators in what appears to be a coordinated campaign.
The Revocation Challenge
Google's response involved both immediate technical mitigation and coordination with certificate authorities. The Chrome update distributed to users included a blocklist of identified fraudulent certificates, preventing the browser from accepting them even if they had not yet been formally revoked through the standard certificate revocation list or OCSP mechanisms.
Formal revocation through certificate authorities is a slower process. Revocation data propagates unevenly across the internet, and not all clients check revocation status before accepting a certificate. The delay between identifying a fraudulent certificate and ensuring that no client will accept it creates a window during which attacks remain viable.
Google did not specify how many certificates were issued, how long they remained valid before detection, or whether the attackers attempted to use them in active man-in-the-middle attacks. The company's statement focused on containment and remediation rather than attribution or tactical details.
Broader Implications for Certificate Transparency
The certificate transparency framework, which Google helped develop and now mandates for all certificates trusted by Chrome, likely played a role in detecting the fraudulent issuances. Certificate transparency logs provide a public, append-only record of all issued certificates, allowing domain owners to monitor for unauthorised credentials.
However, the framework is reactive rather than preventive. It enables detection after issuance, not before. In this case, Google's monitoring systems presumably flagged certificates for its own domains appearing in transparency logs without corresponding internal issuance requests. That detection capability is available to large organisations with dedicated security teams; smaller entities targeted in the same campaign may lack the resources to monitor certificate logs continuously.
The incident also raises questions about the adequacy of domain validation methods. The three primary approaches, DNS-based validation, HTTP-based validation, and email-based validation, all assume that control of the domain's DNS records or web server constitutes proof of ownership. When attackers compromise the DNS layer itself, all three methods fail simultaneously.
Regional Infrastructure Under Pressure
The targeting of three ccTLDs in West Africa and the Pacific suggests either opportunistic exploitation of known weaknesses or a deliberate strategy to compromise less-defended infrastructure. Both Ghana and Sierra Leone have experienced previous incidents involving their national DNS infrastructure. American Samoa's .as domain, while managed by a commercial entity, has been attractive to certain registrants due to its availability and lack of stringent registration requirements.
Certificate authorities are required under industry baseline requirements to perform validation checks, but those requirements do not mandate verification of the security posture of the DNS infrastructure being queried. A certificate authority has no mechanism to distinguish between a legitimate DNS response from a compromised ccTLD and a legitimate response from a secure one.
Google's disclosure did not address whether the attackers maintained persistent access to the compromised ccTLD infrastructure or whether the intrusions were detected and remediated. The company also did not indicate whether other certificate authorities beyond those that issued Google certificates had been exploited in the same manner.
The Path Forward
This incident will likely accelerate discussions within the certificate authority and browser community about additional validation requirements for high-value domains. Proposals have circulated for years regarding multi-perspective validation, in which certificate authorities query DNS records from multiple vantage points to detect localised hijacking, and for extended validation processes that go beyond automated domain control checks.
The challenge lies in balancing security with the operational simplicity that has made TLS certificates ubiquitous. Automated issuance through protocols such as ACME has driven certificate adoption and enabled short-lived certificates that reduce the window of exposure when private keys are compromised. Adding friction to the issuance process risks undermining those gains.
For organisations operating in or serving users in regions where DNS infrastructure security remains uneven, the incident serves as a reminder that certificate monitoring and rapid response capabilities are not optional. The trust model underpinning web security assumes that certain layers of infrastructure remain uncompromised. When they do not, detection and containment speed become the primary defence.



