BREACH WATCH BRIEF High 📋 Breach

Attackers Hijack .gh, .sl, and .as Registries to Obtain Fraudulent Certificates for Google Domains

Attackers breached the Ghana, Sierra Leone and American Samoa ccTLD registries and issued unauthorized HTTPS certificates for Google domains. The incident highlights the need for continuous third‑party risk monitoring and PKI oversight to protect brand integrity.

SeverityHigh
Type📋 Breach
ConfidenceHigh
ReportedOct 7, 2026
Other / Unknown Internet service providers Enterprises with domains in .gh, .sl, .as SaaS platforms relying on TLS for brand protection Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

The registries for .gh, .sl and .as were compromised, allowing threat actors to request and receive valid TLS certificates for Google‑owned hostnames. Google’s internal infrastructure was not directly accessed, but any site under those TLDs could be spoofed with a trusted certificate.

Why it matters for trust and compliance

  • This supply‑chain breach tests the control objective of third‑party oversight and certificate‑issuance monitoring, a requirement that maps to many frameworks via continuous control‑assurance evidence.
  • Demonstrates the need for continuous monitoring of third‑party certificate authorities and registry activity.
  • Provides audit‑ready evidence of due diligence in supply‑chain risk management.

Who is affected

Internet service providers Enterprises with domains in .gh, .sl, .as SaaS platforms relying on TLS for brand protection

Recommended actions

  1. Audit all TLS certificates for domains ending in .gh, .sl, .as and revoke any unauthorized ones.
  2. Require registrars to expose real‑time certificate issuance logs to your monitoring platform.
  3. Integrate registry‑compromise detection into your incident‑response playbook.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.