What happened
Threat actors took over the operational control of three ccTLD registries (Ghana, Sierra Leone, American Samoa). They altered authoritative DNS records and successfully completed domain‑validation checks, allowing them to request and receive valid TLS certificates for Google‑owned domains and other high‑profile sites. Google identified the abuse, revoked the certificates, and blocked them in Chrome via CRLSets while working with the issuing CAs to invalidate the certificates globally.
Why it matters for trust and compliance
- The breach illustrates why a robust third‑party risk management program—complete with continuous monitoring and defensible evidence of vendor security hygiene—is essential for maintaining trust in the TLS ecosystem.
- Continuous monitoring of registrar security posture provides the evidence needed for audit readiness across frameworks.
- Certificate‑Transparency log integration creates a defensible trail that satisfies control‑assurance requirements for TLS integrity.
Who is affected
Technology/SaaS providers Global brands using public‑facing web services Domain registry operators
Recommended actions
- Validate that all domain registrars are covered by a continuous security‑monitoring program and retain audit logs as evidence.
- Implement automated Certificate Transparency monitoring to flag unauthorized certificate issuance.
- Strengthen DNSSEC and require registrars to provide regular security audit reports.