Attackers hijacked three top-level domains—.gh,.sl, and.as—to mint counterfeit TLS certificates for Google and other large organizations. By modifying DNS records at the registry level, they gained the ability to redirect traffic and request certificates for domains they did not own.

TLS certificates bind a domain identity to a public key through digital signatures, allowing browsers to verify they are connecting to authentic sites. The attackers' control over the three ccTLDs let them alter IP addresses for a targeted list of websites, enabling cryptographic impersonation of affected infrastructure.

Google announced the incident Tuesday, saying the attackers created unauthorized certificates for "several Google domains" and "several leading global brands and widely used online services." The company did not name the affected organizations or identify which of its own domains were targeted.

Google pushed updates to Chrome to block the counterfeit certificates it identified and worked with other certificate authorities to implement similar protections across browsers. But the company cautioned that the approach has inherent limits. "Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users," Google said.

The company recommended domain owners check TLS transparency logs for unauthorized certificate issuance on their addresses. "Browser-side intervention should not be relied on to protect your users," Google advised.

The number of unauthorized certificates issued and whether all have been revoked remain unclear. Revoking certificates through browsers is slow; certificate authorities have begun developing faster browser-level blocking methods to respond to such incidents.

This attack echoes the 2011 DigiNotar breach, when hackers compromised the Dutch certificate authority and issued 500 counterfeit certificates for Google and other services—certificates reportedly used to intercept traffic for users in Iran. That incident prompted the industry to build transparency programs that log all certificate issuance, creating a public record that can be audited.

Yet transparency logs alone do not prevent abuse at the registry level. The incident underscores a structural vulnerability: certificate authorities depend on DNS systems they do not control. Companies like Cloudflare and Google are pursuing longer-term fixes, including quantum-safe TLS certificates and HTTPS replacements designed for post-quantum cryptography, but widespread deployment remains years away.