Hackers Hijack Google Domains After Breaching ccTLD Registries
What Happened
According to BleepingComputer, attackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains by breaching third-party operators of country-code top-level domain (ccTLD) registries for Ghana, American Samoa, and Sierra Leone. The attackers modified authoritative DNS records at the registry/operator level, allowing them to redirect or impersonate affected domains. Details on the full scope, attribution, and timeline are still emerging.
Why It Matters
This incident highlights a supply-chain-style weak point in the domain ecosystem: compromising a ccTLD registry operator can cascade into trust failures far beyond the registry itself. Obtaining valid HTTPS certificates for Google domains via DNS manipulation undermines the domain-validation assumptions that certificate authorities and browsers rely on, potentially enabling man-in-the-middle interception, phishing with valid TLS, or traffic redirection for any organization or user resolving through the affected ccTLD infrastructure.
What Defenders Should Watch For
- Monitor Certificate Transparency logs for unexpected certificate issuance covering your organization's domains, especially via domains or subdomains tied to ccTLDs in the affected regions.
- Review DNS resolution paths and authoritative DNS records for any domains dependent on third-party ccTLD operators; watch for unexpected NS, A, or CNAME changes.
- Audit domain registrar and registry account access, including any delegated or reseller relationships, for signs of unauthorized changes.
- Treat unexpected TLS certificate validation failures or mismatches as a potential indicator, not just a configuration issue.
- Consider DNSSEC and CAA record enforcement where feasible to reduce the blast radius of unauthorized certificate issuance.
Developing Story
This is a net-new report with details still emerging; attribution, full scope, and remediation status have not been independently confirmed here. For the latest facts, see the original reporting from BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries.