Hackers hijack Google domains after breaching ccTLD registries
Attackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the .GH, .AS, and .SL country-code TLDs after compromising third-party operators and altering authoritative DNS records. Google says its own systems were not compromised and blocked the certificates in Chrome via CRLSets.
- Attack affected domains in .GH, .SL and .AS; Google systems not compromised
- Altered DNS records let attackers obtain valid TLS certificates for domains they don't own
- Google blocked the certificates in Chrome via CRLSets and worked with CAs to revoke them
- CRLSets only protects Chrome users; other browsers may remain unprotected
Read next
Security