Google blocks unauthorized certificates from DNS hijack of .gh, .sl and .as domains
Attackers hijacked three country-code top-level domains to obtain fraudulent HTTPS certificates for Google and YouTube.

Attackers compromised the DNS infrastructure for Ghana’s .gh, Sierra Leone’s .sl, and American Samoa’s .as domains to obtain unauthorized TLS certificates for Google and YouTube. The fraudulent certificates were issued between September 22 and 27 after attackers altered authoritative DNS records to pass automated ownership checks.
Certificate Transparency logs revealed at least 12 certificates for seven Google and YouTube domains. Let's Encrypt issued 11 of them, and ZeroSSL issued one. All were domain-validated. Google stated that its review of the logs also pointed to other leading global brands and widely used online services being hit by the same attacks.
Certificate issuance and revocation timeline
The fraudulent certificates were logged and revoked across a series of dates in late September and early October. The timeline shows a pattern of activity across the three compromised domains.
| ccTLD | Log Date | Revocation Date | Issuing CA |
|---|---|---|---|
| .gh | September 22 | September 26 | Let's Encrypt & ZeroSSL |
| .sl | September 25 | October 1 | Let's Encrypt |
| .as | September 27 | October 1 | Let's Encrypt |
The shortest gap between a certificate's log entry and its revocation was about a day and a half. The longest was nearly a week. Matthew McPherrin, a Let's Encrypt staff member, confirmed the action. "Yes, certificates for Google and YouTube were issued, and have been revoked," he said on October 7.
Google’s response and mitigation
Google detected the certificates via Certificate Transparency logs the week before its public disclosure on October 6. The company worked with the issuing certificate authorities to revoke all certificates covering its properties. Google's own systems were not breached.
To protect users, Google blocked the unauthorized certificates in Chrome using its CRLSets mechanism for rapid updates. The company stated Chrome users need not take any action. Google also blocked certificates it found for other organizations and contacted those organizations where possible.
However, browser-side blocking has limits. The Chrome Secure Web and Networking Team warned that "we cannot guarantee that our analysis identified every affected domain." Chrome's blocks do not reliably protect people who use other browsers. Google did not say whether any certificate was used to pose as a Google site or read user data.
Protective measures for domain owners
Google advised domain owners to take two specific steps. First, they should monitor Certificate Transparency logs for all domains they own. Second, they should publish a strict Certification Authority Authorization (CAA) DNS record.
A CAA record names the certificate authorities allowed to issue certificates for a domain. Google recommends tying the record to an account at the CA, if the CA supports that option. This measure cannot stop issuance during an active DNS hijack, but it helps regain control afterward. Under industry rules, anyone can also file a Certificate Problem Report with a CA, which must investigate within 24 hours.
Google will continue working with the security community on long-term HTTPS improvements. These include shorter certificate validity periods and reduced domain-validation reuse. For now, the incident shows that controlling a domain’s DNS is enough to obtain trusted certificates. Domain owners should monitor logs and publish strict CAA records to prevent future misuse.





