discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Hijack Google Domains After Breaching ccTLD Registries

Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.

By Bill Toulas·Oct 7·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Hackers Hijack Google Domains After Breaching ccTLD Registries
Image: bleepingcomputer.com

Hackers compromised ccTLD registries and obtained unauthorized HTTPS certificates for Google domains, leading to domain hijacking. Google blocked the certificates and notified affected organizations.

Why it matters

This incident highlights the vulnerability of ccTLD registries and the importance of securing domain name system (DNS) records to prevent unauthorized certificate issuance and domain hijacking.

Hackers tricked a system into giving them fake permission to use Google's domains. Google stopped them and told other companies to be careful too.

Analysis

{"heading_1":"Background on the Incident","paragraph_1":"Google blocked additional certificates connected to the attacks and notified affected organizations where possible, ensuring users of those sites were kept safe as soon as possible.","paragraph_2":"Users of other browsers might not be protected, as CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.","paragraph_3":"Google urges domain owners to monitor CT logs, publish restrictive CAA records, and ensure legitimate DNS control is restored to prevent future attacks.","heading_2":"The Role of Certificate Authorities (CAs)","heading_3":"The Impact on Users and Organizations"}

Key points

  • Hackers compromised ccTLD registries and obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone.
  • Google blocked unauthorized certificates and notified affected organizations, including leading global brands and widely used online services.
  • Users of other browsers might not be protected, as CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.
The Upside

This incident highlights the importance of securing DNS records and verifying domain ownership to prevent future attacks. It also shows that Google is proactive in protecting users and organizations.

The Downside

The incident shows that even major companies like Google can be vulnerable to DNS hijacks. It also suggests that other companies may not have taken the necessary precautions to prevent such attacks.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecuritydnsgooglecyberattack

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Oct 7, 2026

Source

bleepingcomputer.com

Share

Topics

securitycybersecuritydnsgooglecyberattack

Related

More from this desk

Oct 7·bleepingcomputer.com

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud CEO charged with fraud for secretly paying ransomware attackers, charging victims up to $19 million for recovery services.

Oct 7·wired.com

Shaq Got Hacked. Now He’s Pitching for a VPN

Shaq talks about his experience with cyber security and the importance of personal privacy. NordVPN is helping him raise awareness.

Oct 7·bleepingcomputer.com

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.