What happened
Threat actors compromised the operators of the Ghana (.GH), American Samoa (.AS) and Sierra Leone (.SL) country‑code top‑level domains, modified authoritative DNS TXT records, and used the forged records to request and receive legitimate TLS certificates for Google‑owned domains and other organizations. Google responded by blocking the rogue certificates in Chrome via CRLSets and worked with the issuing Certificate Authorities to revoke them, while warning that additional affected domains may remain undiscovered.
Why it matters for trust and compliance
- The breach underscores the importance of a control‑assurance program that continuously monitors third‑party service providers and validates DNS and certificate integrity, providing defensible evidence for supply‑chain risk controls across frameworks such as NIST CSF 2.0.
- Continuous monitoring of registrar activities supplies real‑time evidence for supply‑chain risk controls.
- Certificate Transparency log analysis creates an audit‑ready trail of unauthorized certificate issuance.
Who is affected
Technology SaaS providers (e.g., Google) Enterprises across all sectors that own domains in the compromised ccTLDs
Recommended actions
- Audit DNS records for all domains, especially those managed by third‑party registrars.
- Implement automated Certificate Transparency monitoring and integrate alerts into SOC processes.
- Strengthen third‑party risk contracts to require documented change‑control and regular evidence collection.