---
id: "4ce07708-4c1f-4ad8-819d-d6ed12398573"
kind: "link"
title: "Google Chrome blocks rogue certificates after ccTLD hijacks in Ghana, Sierra Leone, American Samoa"
language: "en"
section: "cctld"
date: "2026-10-07T07:47:12Z"
updated: "2026-10-09T14:33:21Z"
canonical: "https://tldlog.com/l/google-chrome-blocks-rogue-certificates-cctld-hijacks-ghana/"
origin: "master"
translations:
  es: "https://tldlog.com/es/l/chrome-bloquea-certificados-fraudulentos-ataques-cctld-ghana/"
source:
  name: "Google Security"
  url: "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/"
  language: "en-US"
  date: "2026-10-06T09:00:00Z"
---

# Google Chrome blocks rogue certificates after ccTLD hijacks in Ghana, Sierra Leone, American Samoa

## in plain words

Hackers broke into the systems running three country domain extensions - Ghana's .gh, Sierra Leone's .sl, and American Samoa's .as - and used that access to get fake security certificates for websites, including Google's. Chrome, Google's web browser, quickly blocked those fake certificates to keep users safe. Google says people do not need to do anything, but website owners should watch for suspicious certificates issued in their name.

Google's Chrome Secure Web and Networking Team says it detected a series of domain hijacks last week affecting three country-code top-level domains: .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa). The team states the incidents stemmed from compromises of the third-party ccTLD registries themselves, not any breach of Google's own systems. Attackers reportedly altered authoritative DNS records for these namespaces and used that access to obtain unauthorized HTTPS certificates covering various Google domains along with domains belonging to other organizations. Google says it has no reason to suspect wrongdoing by the certificate authorities that issued the fraudulent certificates, since the attacks exploited registry-level DNS control rather than CA failures.

As part of standard incident response, Chrome blocked the unauthorized certificates for Google properties using its CRLSets mechanism, and separately coordinated with the issuing CAs to get the certificates revoked so that browsers other than Chrome would also be protected. After this initial response, analysis of Certificate Transparency log data turned up further organizations apparently hit by the same campaign, including what Google describes as several major global brands and widely used online services. Chrome proactively blocked those certificates too and attempted to notify the affected organizations directly.

Google states that Chrome users need take no action themselves, since the browser's protections apply automatically. However, the company stresses that browser-level blocking should not be treated as a substitute for domain owners securing their own certificates, since its analysis may not have caught every affected domain and Chrome's interventions do not help users of other browsers.

Google recommends that organizations continuously monitor Certificate Transparency logs across their entire domain portfolio, including parked or regional ccTLD properties, and specifically check for unexpected certificate issuance if they operate domains under .gh, .sl, or .as. It also urges publishing restrictive CAA (Certification Authority Authorization) records with ACME account bindings, which limit which CAs can issue certificates and can block attackers from exploiting cached domain validation after control of DNS is restored. Google adds that it will keep working with the wider web community on longer-term fixes, such as shortening certificate validity periods and limiting reuse of domain control validation, through its Chrome Root Program and the newer Chrome Quantum-resistant Root Program.

Source: [Google Security](https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/)

## also covered by

- [bortzmeyer.org](https://www.bortzmeyer.org/piratage-trois-cctld.html) (in French)
- [domainbrief.de](https://domainbrief.de/artikel/angreifer-kapern-gh-sl-und-as-und-erhalten-zertifikate-fuer-google-domains) (in German)
- [circleid.com](https://circleid.com/posts/dns-hijacks-across-three-cctlds-linked-to-32-unauthorized-https-certificates) (in English)
- [thehackernews.com](https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html) (in English)
