Hackers hijack Google domains after breaching ccTLD registries
Executive Summary
Hackers compromised operators of Ghana, American Samoa, and Sierra Leone ccTLD registries, stole unauthorized HTTPS certificates for Google domains, and altered authoritative DNS records to hijack those domains. The attack leveraged third‑party registry access to redirect traffic, potentially enabling phishing or data interception.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-10-07T20:50:13+00:00 - Category: threat-intel
Original Description: Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]
"We must not say every mistake is a foolish one."
— Cicero