Full Report
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted
Analysis Summary
# Incident Report: Multi-ccTLD Registry Hijack and Unauthorized Certificate Issuance
## Executive Summary
Between September 22 and September 27, 2026, attackers compromised three country-code top-level domain (ccTLD) registries (.gh, .sl, and .as), allowing them to hijack authoritative DNS records. Using this control, the attackers obtained 12 unauthorized domain-validated HTTPS certificates for Google and YouTube domains from Let's Encrypt and ZeroSSL. While Google’s internal systems remained secure, the incident created a significant risk for Man-in-the-Middle (MitM) attacks against users in Ghana, Sierra Leone, and American Samoa.
## Incident Details
- **Discovery Date:** Approximately September 29 – October 2, 2026 (Reported by Google as "the week before October 6")
- **Incident Date:** September 22, 2026 – September 27, 2026
- **Affected Organization:** Multiple (Google/YouTube confirmed; others suspected)
- **Sector:** Technology / Critical Internet Infrastructure (ccTLD Registries)
- **Geography:** Ghana (.gh), Sierra Leone (.sl), American Samoa (.as)
## Timeline of Events
### Initial Access
- **Date/Time:** September 22, 2026 (First recorded certificate for .gh)
- **Vector:** Compromise of ccTLD registry infrastructure or administrative accounts.
- **Details:** Attackers gained the ability to modify authoritative DNS records for specific high-value domains within the targeted registries.
### Lateral Movement
- **Details:** The attackers did not move laterally within Google’s network; instead, they moved across different national registry infrastructures (.gh to .sl to .as) over a six-day period.
### Data Exfiltration/Impact
- **Impact:** Unauthorized issuance of 12 HTTPS certificates (11 from Let's Encrypt, 1 from ZeroSSL) for domains including `*.google.com.gh`, `google.sl`, and `youtube.as`. This enabled potential interception of encrypted traffic and credential theft for users visiting these sites.
### Detection & Response
- **Detection:** Discovered via Certificate Transparency (CT) logs and Google's internal monitoring.
- **Response:** Google utilized Chrome CRLSets to block certificates immediately, collaborated with Certificate Authorities (CAs) for revocation, and published a public advisory on October 6.
## Attack Methodology
- **Initial Access:** Registry Hijacking / DNS Hijacking.
- **Persistence:** Control over authoritative DNS records for the duration of the registry compromise.
- **Defense Evasion:** Use of legitimate CAs (Let's Encrypt, ZeroSSL) to issue valid-looking certificates to bypass standard browser warnings.
- **Discovery:** Identifying high-traffic Google/YouTube regional domains.
- **Impact:** Creation of fraudulent certificates for Man-in-the-Middle (MitM) capabilities.
## Impact Assessment
- **Financial:** Undisclosed; costs associated with incident response and registry remediation.
- **Data Breach:** Potential exposure of private data for users in affected regions if MitM attacks were successfully executed.
- **Operational:** Disruption of trust in specific ccTLD registries; emergency revocation and blocking procedures required.
- **Reputational:** High impact for the affected national registries; minimal for Google due to transparent response.
## Indicators of Compromise
- **Behavioral Indicators:**
- Unauthorized changes to authoritative DNS records (A/AAAA/CNAME/TXT) for Google domains.
- Appearance of Google/YouTube certificates in CT logs issued by CAs other than Google Trust Services.
- **Defanged Certificate Issuers:**
- `letsencrypt[.]org` (Unauthorized issuance)
- `zerossl[.]com` (Unauthorized issuance)
## Response Actions
- **Containment:** Chrome deployed CRLSet updates to invalidate the specific serial numbers of the hijacked certificates.
- **Eradication:** CAs (Let's Encrypt and ZeroSSL) revoked all 12 identified certificates between September 26 and October 1.
- **Recovery:** Restoration of proper DNS authority for the affected regional domains.
## Lessons Learned
- **CT Log Utility:** Certificate Transparency remains the primary tool for detecting domain hijacking and unauthorized issuance in near real-time.
- **Registry Vulnerability:** ccTLD registries in smaller or developing jurisdictions may have lower security postures, representing a "weak link" in global internet security.
- **Revocation Latency:** A gap of 1.5 to 7 days between issuance and revocation highlights the need for faster automated revocation mechanisms.
## Recommendations
- **Implement CAA Records:** Organizations should use Certificate Authority Authorization (CAA) DNS records to restrict which CAs are permitted to issue certificates for their domains.
- **Registry Lock:** High-value domains should utilize "Registry Lock" services to prevent unauthorized DNS or ownership changes.
- **CT Monitoring:** Security teams must monitor Certificate Transparency logs for any certificates issued by unauthorized CAs.