# Hackers Hijack Google & Others' Domains via ccTLD Registry Breach

> Hackers compromised ccTLD registries, enabling DNS hijacking of Google and other brands' domains and unauthorized HTTPS certificate issuance.

- Published: 2026-10-07T20:56:27.000Z
- Severity: medium
- Category: Supply Chain
- Tags: Supply Chain Attack, DNS Hijacking, Certificate Transparency, HTTPS Certificates, ccTLD
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/
- Canonical: https://runtimerebel.com/blog/hackers-hijack-google-others-domains-via-cctld-registry-breach

## Key points

- Threat actors hijacked domains and obtained unauthorized HTTPS certificates, enabling impersonation and content serving.
- Affected systems: Domains in .GH, .SL, and .AS ccTLDs, including Google properties and other global brands.
- Remediation: Organizations must monitor Certificate Transparency logs and enforce strict DNS management controls.

## Compromise of ccTLD Registries Leads to DNS Hijacking
Threat actors successfully compromised several country-code top-level domain (ccTLD) registries, specifically those for Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL). This breach enabled them to modify authoritative Domain Name System (DNS) records for various domains, including those belonging to Google, as well as several other leading global brands and widely used online services. The attackers then leveraged this control to obtain unauthorized HTTPS certificates, creating a significant risk of impersonation and malicious content delivery, as reported by [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/). Google emphasized that its internal systems were not compromised in this incident.

### Technical Overview of ccTLD Registry Compromise and DNS Hijacking
The core of this attack involved gaining unauthorized access to third-party operators managing the aforementioned ccTLD registries. With control over these critical DNS infrastructure components, the attackers were able to alter the authoritative DNS records for targeted domains. This modification allowed them to redirect traffic for these domains to infrastructure under their control.

A crucial step in the attack chain was the acquisition of unauthorized HTTPS certificates. Certificate Authorities (CAs) verify domain ownership before issuing certificates, typically by requiring the requester to create a specific TXT record in the domain's DNS. By having control over the authoritative DNS records, the threat actors could satisfy these validation checks, thereby obtaining valid [TLS](/glossary#transport-layer-security-tls) certificates for domains they did not legitimately own. This capability enabled the attackers to impersonate legitimate websites, serve arbitrary content to visitors, and potentially conduct [phishing](/glossary#phishing) campaigns or distribute [malware](/glossary#malware) under the guise of trusted brands.

Google swiftly responded to the incident by blocking the unauthorized certificates for its properties in Chrome via CRLSets, an emergency mechanism designed for rapid certificate revocation. This action extended protection to Chrome users accessing Google's affected domains. The company also worked with the issuing Certificate Authorities to revoke the compromised certificates. Further analysis of Certificate Transparency (CT) logs revealed that other organizations were impacted by the same attack methodology, prompting Google to proactively block these additional certificates in Chrome to safeguard their users.

### Impact and Why It Matters

The incident highlights a critical [vulnerability](/glossary#vulnerability) within the internet's naming infrastructure: the supply chain risk associated with third-party domain registrars and ccTLD operators. While Google's direct systems remained secure, the compromise of a trusted third party allowed attackers to indirectly target Google's domains and those of other high-profile entities. This type of compromise underlines how a weakness in one part of the digital supply chain can have far-reaching implications, extending beyond the immediately breached entity to affect numerous downstream organizations and their users.

The ability to obtain unauthorized HTTPS certificates and perform DNS hijacking poses a severe threat. Users are conditioned to trust websites displaying a valid padlock icon, signifying a secure HTTPS connection. When this trust mechanism is subverted, attackers can convincingly impersonate legitimate services, making it exceedingly difficult for average users to discern malicious sites from genuine ones. This could lead to [credential theft](/glossary#credential-theft), distribution of malicious software, or other forms of fraud. Google's use of CRLSets provides immediate protection for Chrome users, but it's important to recognize that this protection does not extend to users of other browsers, leaving a significant portion of the internet population potentially exposed. Furthermore, Google acknowledged that their analysis might not have identified every single affected domain.

### Actionable Recommendations for Unauthorized HTTPS Certificate Mitigation

Organizations must implement proactive measures to mitigate the risks associated with DNS hijacking and unauthorized certificate issuance.

*   **Monitor Certificate Transparency Logs**: Regularly monitor public [Certificate Transparency log monitoring](https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/) for certificates issued for your domains. Unexpected certificates are a strong indicator of compromise. This allows for early detection of unauthorized issuance.
*   **Enforce DNS Security Best Practices**: Ensure the highest level of security controls for domain name management, including strong authentication (e.g., multi-factor authentication) for registrar accounts and strict [access control](/glossary#access-control) policies for DNS records.
*   **Implement DNSSEC**: While not a silver bullet, DNSSEC helps ensure the authenticity and integrity of DNS data, making it harder for attackers to spoof DNS records undetected.
*   **Utilize Certification Authority [Authorization](/glossary#authorization) (CAA) Records**: While CAA records cannot prevent certificate issuance during an active DNS hijack, they can prevent CAs from issuing additional certificates for your domain using cached validation data after legitimate DNS control is restored. This provides a valuable layer of post-incident control.
*   **Regularly Audit Registrar Configurations**: Periodically review settings and authorized contacts with your domain registrars and ccTLD operators to ensure no unauthorized changes have been made.

For individual users, while Google Chrome offers some protection through CRLSets, caution remains paramount. Always verify the authenticity of a website, especially when prompted for sensitive information, and be wary of unexpected redirects or unusual content on familiar sites. This incident underscores the ongoing need for vigilance across the entire digital ecosystem.

**Related:** [CubePilot DNS Hijacking: How Attackers Intercepted UAV Flight Data](/blog/cubepilot-dns-hijacking-how-attackers-intercepted-uav-flight-data), [ccTLD Hijacks Force Unauthorized Google HTTPS Certificates](/blog/cctld-hijacks-force-unauthorized-google-https-certificates)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/hackers-hijack-google-others-domains-via-cctld-registry-breach
