← All Posts

There you have it! Google just disclosed that attackers hijacked the DNS records for three countr…

October 7, 2026 · 0 likes · 0 comments
AI Cybersecurity
There you have it! Google just disclosed that attackers hijacked the DNS records for three country domains, .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), and used that control to get certificate authorities to issue fake TLS certificates for Google and what Google calls "several leading global brands and widely used online services."

Here is how it worked. Before a certificate authority issues a certificate, it checks that you control the domain, and that check is automated and trusts the DNS records. The attackers changed those records at the registry level, so the checks passed. Google says the certificate authorities followed their procedures correctly and that none of the targeted companies' own servers were breached, which means the whole system did what it was designed to do and still handed out certificates for google.com to people who had no business holding them.

A TLS certificate is what tells your browser it's really talking to google.com, so anyone holding a fake one can pose as that site convincingly, padlock and all.

Google says it blocked every fake certificate it found in Chrome and worked with the authorities to get them revoked, so Chrome users don't need to do anything. But the same statement says "we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users." Google also hasn't said which of its own domains were targeted, who the other brands are, or how many certificates were issued in total.

Some people on tech forums are shrugging because Ghana, Sierra Leone and American Samoa aren't big internet hubs, but the damage depends on which global domains the attackers went after, since the registries could redirect traffic for any domain under them. The last time fake certificates showed up at scale was DigiNotar in 2011, when a compromised Dutch authority issued roughly 500 of them, some reportedly used against users in Iran, and that incident is the reason Certificate Transparency logging exists.

If you own a domain, Google's advice is to watch the Certificate Transparency logs for any certificate issued that you didn't authorize, and to publish restrictive CAA DNS records so attackers can't reuse cached validation data after a hijacked registry gets restored. I'd put both on this week's list.

Full breakdown on UnbiasedHeadlines.com, an unbiased news site built entirely by AI agents. No spin, just the facts: https://lnkd.in/g5Kg7FiW
View original on LinkedIn →