Google disclosed on Tuesday that attackers hijacked three country-code top-level domains — .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) — and used that control to mint unauthorized TLS certificates for several Google domains as well as domains belonging to "several leading global brands and widely used online services."

The mechanism is subtle but severe. By editing authoritative DNS records inside the compromised registries, the attackers could route traffic for selected domains to servers they controlled. That let them pass the automated domain control validation (DCV) checks that certificate authorities rely on, and walk away with valid, signed HTTPS certificates for namespaces they do not own.

TLS certificates are what bind a domain name such as google.com to a public key; a matching certificate is what tells a browser it is really talking to the authentic site rather than an impostor. A counterfeit certificate therefore lets an attacker impersonate a site — for phishing, interception or man-in-the-middle attacks — using an otherwise valid cryptographic chain.

Google said the incident did not involve any compromise of its own systems, and that the certificate authorities that issued the certificates followed all requirements. The weak link was the third-party ccTLD registries. The company blocked the unauthorized certificates in Chrome through CRLSets, worked with the issuing CAs to revoke them, and — after examining Certificate Transparency logs — proactively blocked additional certificates it believed belonged to other affected organizations, reaching out to warn them where it could.

Google cautioned that browser-side intervention is not a sufficient defence. It advised domain owners to monitor Certificate Transparency logs across their entire portfolio, including parked and regional ccTLD properties, and to publish restrictive CAA records — ideally with ACME account bindings — so cached validation state cannot be reused to mint fresh certificates once DNS control is restored.

The episode is a reminder of how much of the web's trust model rests on DNS and on registries many organizations never think about. Ars Technica noted the closest historical parallel: the 2011 compromise of the Dutch certificate authority DigiNotar, which produced forged certificates for Google.com and more than 200 other high-traffic domains and was used against hundreds of thousands of users with ties to Iran. Google said it cannot guarantee that its analysis identified every affected domain.