BREACH WATCH BRIEF High 📋 Breach

Hackers Hijack Google and Global Domains via Compromised ccTLD Registries

Attackers breached the operators of .GH, .SL and .AS ccTLD registries, altered DNS records and obtained valid HTTPS certificates for Google and other brands. The incident highlights the need for continuous third‑party risk monitoring and certificate‑transparency visibility to maintain audit‑ready control assurance.

SeverityHigh
Type📋 Breach
ConfidenceHigh
ReportedOct 7, 2026
Technology & SaaS Technology SaaS providers (e.g., Google) Enterprises across all sectors that own domains in the compromised ccTLDs Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

Threat actors compromised the operators of the Ghana (.GH), American Samoa (.AS) and Sierra Leone (.SL) country‑code top‑level domains, modified authoritative DNS TXT records, and used the forged records to request and receive legitimate TLS certificates for Google‑owned domains and other organizations. Google responded by blocking the rogue certificates in Chrome via CRLSets and worked with the issuing Certificate Authorities to revoke them, while warning that additional affected domains may remain undiscovered.

Why it matters for trust and compliance

  • The breach underscores the importance of a control‑assurance program that continuously monitors third‑party service providers and validates DNS and certificate integrity, providing defensible evidence for supply‑chain risk controls across frameworks such as NIST CSF 2.0.
  • Continuous monitoring of registrar activities supplies real‑time evidence for supply‑chain risk controls.
  • Certificate Transparency log analysis creates an audit‑ready trail of unauthorized certificate issuance.

Who is affected

Technology SaaS providers (e.g., Google) Enterprises across all sectors that own domains in the compromised ccTLDs

Recommended actions

  1. Audit DNS records for all domains, especially those managed by third‑party registrars.
  2. Implement automated Certificate Transparency monitoring and integrate alerts into SOC processes.
  3. Strengthen third‑party risk contracts to require documented change‑control and regular evidence collection.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.