Technology
Attackers hijacked three country-code domains to get fake Google certificates, Chrome team says
Google says intruders who took over the .gh, .sl and .as registries obtained unauthorized HTTPS certificates for several Google domains and other major brands. Chrome has blocked the ones it found, but Google warns it may not have caught them all.
Published: October 6, 2026 · Updated: October 6, 2026 · 3 min read
Attackers took control of the registries behind three country-code internet domains and used that access to obtain unauthorized HTTPS certificates for several Google domains and for sites run by other large organizations, Google disclosed Tuesday. In a post from its Chrome team, the company said it learned last week of domain hijacks in the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) namespaces. Google said its own systems were not breached. The attackers instead compromised the third-party registries that run those suffixes, which put every domain ending in .gh, .sl or .as at risk.
With control of the registries, the attackers changed the authoritative DNS records and nameserver delegations for selected domains, Ars Technica reported. That allowed them to pass the automated domain-control checks that certificate authorities run before issuing a certificate, which ask an applicant to prove it controls the domain. Google said it has no reason to believe the certificate authorities that issued the certificates did anything wrong, and Ars noted that the infrastructure of the affected domain owners was not compromised either.
The stakes are high because TLS certificates are how browsers confirm they are talking to the real website rather than an impostor. A certificate binds a domain name such as google.com to a public key, and anyone holding an unauthorized certificate can cryptographically impersonate the site, Ars explained. It pointed to the 2011 hack of the Dutch certificate authority DigiNotar, when attackers minted counterfeit certificates for Google.com and more than 200 other high-traffic domains that were used against at least 300,000 people with ties to Iran.
Google said it blocked the certificates covering its own properties in Chrome using CRLSets and worked with the issuing authorities to have them revoked, so that people using other software would also be protected. CRLSets are “the primary means by which Chrome quickly blocks certificates in emergency situations,” according to the Chromium project. Certificate Transparency logs, the public records in which certificates trusted by Chrome must be disclosed, then pointed to more victims, “including several leading global brands and widely used online services.” Chrome blocked those certificates too, and Google said it contacted affected organizations where it could. Chrome users do not need to do anything to be protected, the company said.
Google did not identify the affected domains or name the other organizations. Ars said it was not clear how many unauthorized certificates were issued or whether all of those for non-Google sites had been blocked, and noted that formal revocation is slow and cumbersome. Google itself cautioned against treating the browser fix as complete. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” it wrote.
The company urged domain owners to monitor Certificate Transparency logs for unexpected certificates across their whole portfolio, including parked or regional country-code domains, and said anyone operating a .gh, .sl or .as domain should review recent entries. It also recommended publishing restrictive Certification Authority Authorization (CAA) records, which tell certificate authorities who may issue certificates for a domain. Google said CAA cannot stop issuance during an active hijack, but because authorities may cache and reuse completed validation checks, a restrictive policy restored afterward can stop an attacker from minting new certificates once the hijack ends. Google added that it will keep pushing for shorter certificate lifetimes and less reuse of validation through its Chrome Root Program.
The disclosure came on the same day that the Canadian Internet Registration Authority, the not-for-profit that manages the .ca domain, released its 2026 Cybersecurity Survey. The online survey of 503 cybersecurity decision-makers, conducted by The Strategic Counsel in June and July, found that 39 per cent of organizations had experienced an attempted or successful cyberattack or incident, down from 43 per cent in 2025. Only 67 per cent said their cybersecurity budget was sufficient, down from 74 per cent, and 75 per cent of organizations hit by a successful ransomware attack said they paid the ransom.
“Cybersecurity challenges are increasing while resources are becoming harder to secure,” Jon Ferguson, CIRA’s vice-president of cyber and DNS, said, according to The Canadian Press. The survey also found that 91 per cent of respondents say it matters that their cybersecurity records are stored and processed in Canada. CP noted that, according to the Canadian Research Insights Council, online surveys of this kind cannot be assigned a margin of error. Google’s notice named only the three hijacked namespaces.
Sources: Google Chrome team blog (Oct. 6, 2026); Ars Technica; Chromium project, CRLSets; CIRA 2026 Cybersecurity Survey; The Canadian Press via Winnipeg Free Press.
Sources
- Google Chrome team blog · company
- Ars Technica · news
- Chromium project, CRLSets · company
- CIRA 2026 Cybersecurity Survey · organization
- The Canadian Press via Winnipeg Free Press · news
Newsletter
News. Context. What matters.
One essential briefing, written for people who would rather understand the story than scroll it.
Unsubscribe anytime. We don’t sell addresses.
Recommended
Technology
Signal tells senators it won’t comply with Bill C-22’s encryption and metadata powers
The encrypted messaging service’s policy chief told a gathering of senators and lawmakers that the lawful access bill’s powers over encryption keys, metadata and technical changes would ‘fundamentally break Signal.’
Technology
TELUS completes first satellite-to-smartphone test with AST SpaceMobile, targets service within a year
The test linked TELUS’s wireless network with AST’s low-Earth-orbit satellites for calls, texts and data on ordinary phones, as TELUS chases Rogers and Bell in closing Canada’s coverage gaps from space.
Technology
OpenAI will watermark ChatGPT text in the EU only, leaving Canadian users out for now
The invisible textGrain signal, built to meet the EU AI Act, rolls out to ChatGPT and Codex users in Europe over the coming weeks, while API customers worldwide, including in Canada, can switch it on themselves.