Hackers obtain counterfeit TLS certificates for Google and other large services

What happened
The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS (the system that turns a domain name into an address) records for selected domains within those namespaces. Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked. Google is an Internet and software company based in Mountain View.
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs. Attackers hijacked three top-level domains and used their control to mint counterfeit TLS (the encryption that secures a connection to a website) certificates for Google and other large organizations, Google said Tuesday. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key.
Sources & evidence
- Ars Technica Reporting source
Hackers obtain counterfeit TLS certificates for Google and other large services ↗
https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/