BREACH WATCH BRIEF High 👤 Breach

Hackers Hijack Three ccTLD Registries to Issue Unauthorized HTTPS Certificates for Google Domains

Attackers seized control of the .gh, .sl and .as country‑code domain registries and used that access to obtain fraudulent HTTPS certificates for Google and other large brands. The incident underscores the importance of continuous third‑party risk monitoring and certificate‑transparency checks for audit‑ready control assurance.

SeverityHigh
Type👤 Breach
ConfidenceHigh
ReportedOct 7, 2026
Technology & SaaS Technology/SaaS providers Global brands using public‑facing web services Domain registry operators Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

Threat actors took over the operational control of three ccTLD registries (Ghana, Sierra Leone, American Samoa). They altered authoritative DNS records and successfully completed domain‑validation checks, allowing them to request and receive valid TLS certificates for Google‑owned domains and other high‑profile sites. Google identified the abuse, revoked the certificates, and blocked them in Chrome via CRLSets while working with the issuing CAs to invalidate the certificates globally.

Why it matters for trust and compliance

  • The breach illustrates why a robust third‑party risk management program—complete with continuous monitoring and defensible evidence of vendor security hygiene—is essential for maintaining trust in the TLS ecosystem.
  • Continuous monitoring of registrar security posture provides the evidence needed for audit readiness across frameworks.
  • Certificate‑Transparency log integration creates a defensible trail that satisfies control‑assurance requirements for TLS integrity.

Who is affected

Technology/SaaS providers Global brands using public‑facing web services Domain registry operators

Recommended actions

  1. Validate that all domain registrars are covered by a continuous security‑monitoring program and retain audit logs as evidence.
  2. Implement automated Certificate Transparency monitoring to flag unauthorized certificate issuance.
  3. Strengthen DNSSEC and require registrars to provide regular security audit reports.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.