MediumII Cyber Warfare & Critical Infrastructure6 October 2026, Tuesday
Attackers hijack three national domain registries to obtain Google certificates
Google disclosed on 6–7 October that the .gh, .sl and .as country-code domain registries had been compromised. The Hacker News found 12 certificates in public logs issued for seven domains, including google.com.gh and youtube.as; Google confirmed they had been revoked as of 7 October.
The Hacker News reported on 7 October that Ghana's .gh registry was compromised on 22 September, Sierra Leone's .sl on 25 September and American Samoa's .as on 27 September. In all three registries the attackers altered authoritative DNS records, which determine which server a domain points to, and redirected traffic to their own infrastructure. That let them obtain valid TLS certificates, the basis of the padlock in the browser, for seven domains they did not own. BleepingComputer said the attackers targeted the third-party operators running the three registries.
The Hacker News found 12 certificates in certificate transparency logs, the public ledgers in which every issued certificate is recorded. Let's Encrypt issued 11 of them and ZeroSSL one. All 12 were domain-validated certificates, which require only proof of DNS control. Google confirmed that the certificates issued for Google and YouTube had been revoked as of 7 October. BleepingComputer reported on 7 October that Google blocked the certificates in Chrome through its CRLSet list and said its own systems were not affected in any way.
The two sources give different disclosure dates: The Hacker News says Google announced the breach on 6 October, BleepingComputer on 7 October. The attackers had not been identified as of 7 October, and whether the certificates were abused could not be verified. The constraint here is that the internet's chain of trust breaks at its weakest link. Once the operators of three small national registries fell, valid certificates could be obtained for global brands' domains under those extensions.
Talay assessment
Bottom line
The attack shows that trust on the internet depends on the security of small national registries. Google's revocation of the certificates closed this case. Yet three registries falling within five days suggests other registries in the same operator chain may also be targets. The most likely path is that certificate authorities introduce extra validation for country-code domains.
Likely effects
- User securityNegativeWeeks
Fake sites with valid certificates can harvest credentials without triggering browser warnings; the window stays open until the certificate is revoked.
- Certificate authoritiesUncertain1–6 months
Authorities that issue certificates automatically may be forced to tighten validation that relies solely on DNS control for country-code domains.
- Small national registriesUncertain6 months+
Because developing countries' registries also host government and bank sites, they face pressure to invest in security.
Possibilities, ranked
- 1Similar registry hijacks emerge50%
Scans of certificate transparency logs uncover suspicious certificates under other country-code registries.
Watch: New certificates in transparency logs for major brand and bank domains under country-code extensions
- 2The incident stays limited to three registries35%
Revocations and operator fixes close the incident and no new victims are disclosed.
Watch: Incident reports from the registry operators in Ghana, Sierra Leone and American Samoa
- 3The attack is tied to a state group15%
A security firm or Google attributes the attack to a state-backed group.
Watch: An attribution report from Google's Threat Analysis Group or Mandiant
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- National registries compromised▼ 3
- Unauthorised certificates issued▼ 12
- Domains affected▼ 7