Cybercrime
Google Domains Impacted by Recent ccTLD Hijacks
Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains.

By
|
October 9, 2026 (7:43 AM ET)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Google Domains Impacted by Recent ccTLD Hijacks https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/) [+ Whatsapp](whatsapp://send?text=Google Domains Impacted by Recent ccTLD Hijacks https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/) + Email

Google has disclosed that several of its domains were affected by a recent hijack of third-party country-code top-level domains (ccTLDs).
The incident occurred last week and targeted the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) ccTLDs, putting all domains with those suffixes at risk.
“During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” the internet giant says .
According to Google, the Certification Authorities (CAs) that issued the certificates are not to be blamed, given the nature of the attacks.
Immediately after learning of the incident, Google blocked the unauthorized certificates for its domains in Chrome and worked with the issuing CAs to revoke them.
Analysis of Certificate Transparency (CT) log data revealed that multiple other organizations, including global brands and popular online services, have been affected.
Advertisement. Scroll to continue reading.
“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome. Where possible, we reached out to impacted organizations to alert them to our findings and actions,” Google says.
The internet giant notes that, while it took steps to identify and block the unauthorized certificates, certain domains might still be affected.
Google encourages domain owners to monitor CT logs for all their domains, especially for those in .gh, .sl, or .as, and to publish restrictive CAA DNS records to ensure safeguards after DNS control has been restored.
“Because CAs are permitted to cache and reuse completed domain control validation (DCV) checks for subsequent issuance, restoring a restrictive CAA policy, especially one that restricts issuance to specific authorized accounts and validation methods, prevents an attacker from using cached validation state to mint new certificates after a hijack ends,” Google notes.
Related: Chrome 155 Update Patches 247 Vulnerabilities
Related: Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Related: Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
Related: Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Written By
Ionut Arghire is an international correspondent for SecurityWeek.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
More from Ionut Arghire
- Cisco Patches a Dozen Critical Vulnerabilities
- SonicWall and Splunk Patch Critical Vulnerabilities
- Rein Security Raises $25 Million to Guard AI Agents at Runtime
- Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
- FortiBleed Attackers Locking Victims Out of Fortinet Devices
- Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
- Chrome 155 Update Patches 247 Vulnerabilities
- ASOS Confirms Cyberattack, Data Breach
Latest News
- OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
- Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
- US Disrupts Chinese State-Sponsored Hacking Tools
- Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
- Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Trending
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
## Webinar: AI Is Accelerating Risk. Can Your IT Operations Keep Up?
October 14, 2026
Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.
## Virtual Event: Zero Trust & Identity Strategies Summit 2026
October 14, 2026
Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.
People on the Move
Rapid7 has named Rik Ferguson as VP of Security Intelligence.
Cytactic has appointed Tim Brown as CSO.
Scott Simkin has joined Vega as CMO.
Expert Insights
## AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb)
## Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin)
## Begin at the End: How to Enable Agentic Remediation

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael)
## “We Think the Security Control Is Working” Is No Longer Good Enough

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar)
## This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. (Matt Honea)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Google Domains Impacted by Recent ccTLD Hijacks https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/) [+ Whatsapp](whatsapp://send?text=Google Domains Impacted by Recent ccTLD Hijacks https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/) + Email
Popular Topics
Security Community
- Virtual Cybersecurity Events
- Webcast Library
- CISO Forum
- AI Risk Summit
- ICS Cybersecurity Conference
- Cybersecurity Newsletters
Stay Intouch
About SecurityWeek
News Tips
Got a confidential news tip? We want to hear from you.
Advertising
Reach a large audience of enterprise cybersecurity professionals
Daily Briefing Newsletter
Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox.
Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.
