Attackers compromised three country code top-level domains—.gh,.sl and.as—and exploited that control to issue unauthorized TLS certificates for Google and other major organizations, Google disclosed Tuesday.
The attackers modified authoritative DNS records within those namespaces, which gave them enough leverage to bypass automated domain control validation. Certificate authorities then issued x.509 certificates linking Google's domains and those of other targets to public keys the attackers controlled.
TLS certificates are the cryptographic foundation of HTTPS. An attacker holding a valid certificate for google.com can intercept traffic intended for Google's servers and decrypt it in real time—effectively bypassing every security layer that depends on domain ownership. For financial services, email, and cloud infrastructure, this is catastrophic.
Google responded by updating Chrome to revoke the identified unauthorized certificates and worked with issuing certification authorities to pull them from circulation. But the company was direct about the limits of browser-level blocking: Chrome users are protected, but users of Firefox, Safari, and other browsers remain vulnerable to any certificates the attackers issued but Google hasn't yet discovered.
Google did not name which of its own domains were affected or identify any of the compromised organizations. The company also did not disclose how many unauthorized certificates were issued in total.
The vulnerability reflects a structural problem in internet certificate infrastructure. Domain control validation—the mechanism that confirms you own a domain before a certificate is issued—relies on DNS lookups. An attacker who controls your DNS records can satisfy that validation instantly. Once issued, a certificate remains valid for months. Revocation through the standard process takes weeks or longer.
Google advised domain owners to monitor Certificate Transparency logs for unexpected certificate issuance and to publish restrictive CAA (Certification Authority Authorization) DNS records, which limit which certificate authorities can issue certificates for a domain. These measures offer protection once DNS control is regained, but they provide no defense during an active compromise.
The incident exposes why ccTLD operators—the registries that run.gh,.sl,.as and hundreds of others—are attractive targets. A single breach at a country registry can undermine the certificate trust model for every domain registered under that TLD. Unlike attacks on individual domain registrars, which affect customers domain-by-domain, a ccTLD compromise scales instantly across an entire namespace.

