Hackers Exploit Country-Code Registry to Illegally Issue HTTPS Certificates

Domains tied to Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) were recently compromised as hackers hijacked control over the registries of those top-level country-code domains. Using the breach, attackers obtained unauthorized HTTPS certificates for Google properties and other organizations. Chrome automatically blocked the rogue certificates while Google coordinated with certificate authorities to revoke them.

How the Threat Unfolded

Google revealed on October 6 that the intrusion had been detected the previous week. The hijacking involved changes to authoritative DNS records—the systems that declare which servers are legitimate for each domain. By altering these records, attackers can pass domain control validation checks used by certificate authorities (CAs), allowing them to issue certificates without the actual domain owners’ knowledge.

The compromised TLDs—.gh, .sl, and .as—meant that any domain under those endings could potentially be impersonated. Notably, while certificates were issued for some Google-owned domains, Google clarified that its own internal systems weren’t breached and that the issuing authorities themselves had followed standard procedures; the issue stemmed from the sustainable trust model being disrupted by the registry compromise.

Containment and Response

Google’s browser, Chrome, moved swiftly: it blocked the inappropriate certificates using CRLSets, its emergency revocation mechanism. In addition, Google worked with the affected CAs to formally revoke the certificates so that clients beyond Chrome would recognize the removal. As investigations progressed, CAs were found to have issued unauthorized certs not just for Google but for others—major brands and services alike. These too were blocked in Chrome, and affected organizations were notified when possible.

While Chrome raises no action needed by users to gain protection, Google warned that its discovery may not cover every wrongfully issued certificate. And it emphasized that Chrome’s protections don’t universally apply—other browsers and non-browser clients may remain vulnerable.

Preventive Measures Advised

Domain owners under those affected TLDs are urged to review certificates issued to their domains recently—especially any that they didn’t request. Tools exist to monitor Certificate Transparency logs, which can flag questionable issuance. Organizations should also enable Certification Authority Authorization (CAA) records to restrict which CAs may issue certs for their domains, and define explicit validation methods.

Longer-term defenses include using shorter-lived certificates and limiting reuse of any domain validation proofs. Such policies help mitigate risk both during a hijack and after control is restored. Google also points to changes being made in the broader certificate security environment to improve resilience.

This incident highlights the fragility of DNS-based trust in the TLS/HTTPS ecosystem. A breach at a registry level disrupts foundational security — allowing bad actors to impersonate domains even without hacking the website itself. Going forward, registry operators holding country-code TLDs must strengthen governance and security over their authoritative servers. For domain owners and CAs, vigilance—via monitoring, restrictive policies, and transparency—is not optional; it’s essential. Watch for further disclosures on which domains were affected and whether browsers beyond Chrome are able to update protections accordingly.