Google disclosed that attackers compromised third-party operators behind the country-code top-level domains for Ghana (.GH), Sierra Leone (.SL), and American Samoa (.AS), using that access to alter authoritative DNS records and obtain fraudulent HTTPS certificates for several Google domains. Google emphasized that its own systems were not breached in the incident.
By gaining control of DNS records for the affected ccTLDs, the threat actor was able to complete domain validation checks with certificate authorities, which typically require requesters to publish a TXT record containing a value supplied by the CA. With that validation satisfied, the attackers obtained valid TLS certificates for domains they did not legitimately own, then pointed those domains to infrastructure under their control. This allowed them to impersonate legitimate brands and serve arbitrary content to visitors over a connection that would appear secure in the browser.
Scope beyond Google
After the initial mitigation, Google scoured Certificate Transparency logs and found evidence that the same campaign had affected additional organizations, including what it described as several leading global brands and widely used online services. Google proactively blocked those certificates in Chrome as well, though it has not named the other affected organizations.
Mitigation and limits
Google used Chrome’s CRLSets mechanism, an emergency blocklist for revoked or untrusted certificates, to immediately stop Chrome from trusting the fraudulent certificates. It also worked with the issuing certificate authorities to revoke them outright, saying it has no reason to believe those CAs acted improperly.
Google cautioned that Chrome users do not need to take any action, but warned that its detection may not have caught every affected domain, and that CRLSets protections do not extend to users of other browsers. The company did not disclose the identity of the attackers or the total number of certificates confirmed to be compromised.
Recommendations for domain owners
- Monitor Certificate Transparency logs across an entire domain portfolio, including parked or unused domains.
- Publish restrictive Certification Authority Authorization (CAA) records to limit issuance to authorized ACME accounts and validation methods.
Google noted that CAA records cannot stop certificate issuance during an active DNS hijack, but they do prevent attackers from obtaining further certificates using cached domain validation once legitimate DNS control has been restored. Security teams managing domains under .GH, .SL, or .AS, or any brand with a presence in those ccTLDs, should treat this as a prompt to audit CT logs and tighten CAA policy now.
