$ techbeacon▋
Breaches

Hackers Exploit Ghana, Sierra Leone and American Samoa TLD Registries to Forge Google SSL Certificates

Hackers Exploit Ghana, Sierra Leone and American Samoa TLD Registries to Forge Google SSL Certificates

Security researchers disclosed on October 6 that cyber‑actors successfully compromised the registry operators for three country‑code top‑level domains – .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) – and used that foothold to obtain legitimate‑looking HTTPS certificates for a number of Google‑owned web addresses.

The intrusion gave the attackers the ability to manipulate the domain‑validation process that certificate authorities (CAs) rely on to confirm ownership before issuing a TLS certificate. By controlling the registries, the threat actors could present false proof of control for any domain ending in the affected suffixes, prompting CAs to issue certificates that would be trusted by browsers.

Google clarified that its internal systems were not breached; the compromise occurred at the registry level, meaning any site using the compromised TLDs could potentially be spoofed with a valid certificate. The unauthorized certificates were tied to Google domains, raising the risk that users could be directed to malicious sites that appear authentic because of the trusted encryption indicator.

In response, Google notified the affected registry operators and the relevant certificate authorities, urging immediate remediation and revocation of the fraudulent certificates. The company also emphasized that standard browser checks remain in place and that users should continue to rely on other security cues, such as URL consistency and reputable sources, when navigating to Google services.

The episode underscores a broader concern about the trust chain that underpins the public key infrastructure. While CAs verify domain ownership through registrars, a breach at the registrar level can effectively undermine that verification, enabling attackers to create certificates that browsers automatically trust.

Experts say the incident will likely prompt tighter validation procedures, including additional checks beyond simple registry confirmation, and may accelerate discussions about alternative models for certificate issuance. Registry operators are expected to patch the vulnerabilities that allowed the takeover and to cooperate with the global security community to restore confidence.

For end users, the immediate impact is limited, but the situation serves as a reminder to stay vigilant. Even when a site displays the padlock icon, users should verify that the URL matches the intended destination and be cautious of unsolicited redirects, especially when accessing sensitive services.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related