Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Here’s what connects the Cornell alleged rape case to those before: accused men not being held to serious account | Emma Brockes

    October 8, 2026

    Most UK diplomats to leave East Jerusalem consulate, Israel says, as Miliband says ‘vital services’ to remain

    October 8, 2026

    Polanski’s final pitch in Holborn by-election: I’ll keep Burnham honest – POLITICO

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Here’s what connects the Cornell alleged rape case to those before: accused men not being held to serious account | Emma Brockes
    • Most UK diplomats to leave East Jerusalem consulate, Israel says, as Miliband says ‘vital services’ to remain
    • Polanski’s final pitch in Holborn by-election: I’ll keep Burnham honest – POLITICO
    • British consulate in East Jerusalem will stay open as UK mission, says Ed Miliband | Foreign policy
    • Interview with Corriere della Sera
    • Tropical Storm Isaias Set to Be First Atlantic Hurricane of 2026 Season
    • Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
    • SEC and CFTC Crypto Rules ‘Fall Short’ of Clarity, Says Rep. French Hill
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers hijack Google domains after breaching ccTLD registries

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.

    Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but “did not involve a compromise of Google’s systems.”

    By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don’t own.

    CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.

    Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.

    This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.

    Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.

    The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.

    After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.

    “Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained.

    “To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”

    CRLSets is a Chrome “emergency mechanism” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.

    However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.

    The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.

    “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.

    Google urges domain owners to:

    • Monitor CT logs across their entire domain portfolio, including parked domains.
    • Publish restrictive Certification Authority Authorization (CAA) records as needed to limit issuance to authorized ACME accounts and validation methods.

    Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.

    The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    breaching ccTLD Domains Google hackers hijack Registries
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

    Fuel prices added to Google Maps as petrol and diesel costs soar

    FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    Crypto media firm Cointelegraph is looking for a buyer after Google penalty crushed web traffic

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Here’s what connects the Cornell alleged rape case to those before: accused men not being held to serious account | Emma Brockes

    October 8, 2026

    Most UK diplomats to leave East Jerusalem consulate, Israel says, as Miliband says ‘vital services’ to remain

    October 8, 2026

    Polanski’s final pitch in Holborn by-election: I’ll keep Burnham honest – POLITICO

    October 8, 2026

    British consulate in East Jerusalem will stay open as UK mission, says Ed Miliband | Foreign policy

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Here’s what connects the Cornell alleged rape case to those before: accused men not being held to serious account | Emma Brockes

    October 8, 2026

    Most UK diplomats to leave East Jerusalem consulate, Israel says, as Miliband says ‘vital services’ to remain

    October 8, 2026

    Polanski’s final pitch in Holborn by-election: I’ll keep Burnham honest – POLITICO

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.