Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Executive Summary

In early October, attackers compromised the registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), enabling them to issue unauthorized HTTPS certificates for multiple Google domains. Google confirmed the breach on Oct 6, noting that its own systems were not affected. The compromised certificates could allow attackers to impersonate Google sites over encrypted connections, posing a significant security risk for any domain ending in the affected ccTLDs.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-07T18:48:17+00:00 - Category: threat-intel

Original Description: Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted

"These days people seek knowledge, not wisdom. Knowledge is of the past, wisdom is of the future."

— Vernon Cooper
Source: The Hacker News