
Attackers Hijacked .gh .sl .as Registries for 12 Unauthorized Google Certificates via DNS Changes
Registry-level DNS hijacks enabled unauthorized certificates for Google domains under .gh, .sl, and .as, exposing risks in domain validation. CT logs provided rapid detection while CRLSets and revocations contained the threat. Patterns suggest repeated exploitation of smaller ccTLDs for trusted signing abuse.
The compromise allowed issuance of certificates after attackers demonstrated domain control through DNS modifications at the registry level. CT logs from ctlogs.dev and Cert Spotter recorded the certificates, with Let's Encrypt issuing eleven and ZeroSSL one. All were revoked within days via CRLSets and direct CA action, limiting exposure to encrypted impersonation attacks. Google confirmed no internal breach but noted other unnamed brands were likely targeted by the same method.
Google Trust Services: At least one additional ccTLD registry compromise detected via CT within 90 days
Sources (3)
- [1]The Hacker News(https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html)
- [2]Let's Encrypt Community Forum(https://community.letsencrypt.org/t/certificates-issued-for-google-domains-during-hijack/2026)
- [3]Cert Spotter CT Logs(https://sslmate.com/certspotter)