Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Attackers who took control of three country-code top-level domains (ccTLDs) used that access to obtain HTTPS certificates for several Google domains and for domains run by other large organizations, Google disclosed on Tuesday.

Attackers compromised the third-party operators of the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) ccTLDs, putting every domain under those endings at risk, and then changed the authoritative DNS records.
“These incidents did not involve a compromise of Google’s systems,” the company said.
“Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” it added.
Google learned of the hijacks last week and did not say how the registries were compromised, who is behind the attacks, or when they began.
Google blocked the unauthorized certificates for its own properties in Chrome through CRLSets, a list Chrome downloads in the background to block revoked certificates. It also worked with the issuing CAs to revoke those certificates, so users of other browsers and clients are protected too.
Certificate Transparency (CT) log data then revealed other organizations believed to be hit by the same attacks, among them several large global brands and popular online services. These were blocked in Chrome as well, and Google contacted the affected organizations where it could.
“Chrome users do not need to take any action to be protected,” Google wrote.
The company warned that browser-side blocking should not be the only line of defense. Due to the complexity of DNS hijacks, it said, “we cannot guarantee that our analysis identified every affected domain.” It noted that Chrome’s interventions do not reliably protect people using other browsers.
Google plans to keep working with the wider community to limit the damage that DNS and routing compromises can cause.
“To keep our users safe, we are committed to long-term HTTPS ecosystem improvements, such as reducing certificate validity and DCV reuse, through the Chrome Root Program and the new Chrome Quantum-resistant Root Program,” the company concluded.