Hackers Hijack Google Domains After Breaching ccTLD Registries
Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.
Intelligence analysis by Qwen 2.5 (3B)

Hackers compromised ccTLD registries and obtained unauthorized HTTPS certificates for Google domains, leading to domain hijacking. Google blocked the certificates and notified affected organizations.
Hackers tricked a system into giving them fake permission to use Google's domains. Google stopped them and told other companies to be careful too.
Analysis
{"heading_1":"Background on the Incident","paragraph_1":"Google blocked additional certificates connected to the attacks and notified affected organizations where possible, ensuring users of those sites were kept safe as soon as possible.","paragraph_2":"Users of other browsers might not be protected, as CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.","paragraph_3":"Google urges domain owners to monitor CT logs, publish restrictive CAA records, and ensure legitimate DNS control is restored to prevent future attacks.","heading_2":"The Role of Certificate Authorities (CAs)","heading_3":"The Impact on Users and Organizations"}
Key points
- Hackers compromised ccTLD registries and obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone.
- Google blocked unauthorized certificates and notified affected organizations, including leading global brands and widely used online services.
- Users of other browsers might not be protected, as CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.
This incident highlights the importance of securing DNS records and verifying domain ownership to prevent future attacks. It also shows that Google is proactive in protecting users and organizations.
The incident shows that even major companies like Google can be vulnerable to DNS hijacks. It also suggests that other companies may not have taken the necessary precautions to prevent such attacks.



