# Google says attackers hijacked domain records to obtain unauthorized TLS certificates

_Published Tuesday, October 6, 2026 at 7:15 PM EDT · Security · Latest · Tier 2 — Notable_

![Google says attackers hijacked domain records to obtain unauthorized TLS certificates — Primary](https://cdn.arstechnica.net/wp-content/uploads/2026/10/broken-https-tls-1152x648.jpg)

Attackers hijacked three country code top-level domains and obtained unauthorized TLS certificates for Google and other large organizations, Google said Tuesday. They modified authoritative DNS records within .gh, .sl and .as to pass automated checks that validate control of a domain. The certificates allow attackers to cryptographically impersonate affected Internet infrastructure.

Google updated Chrome to block the unauthorized certificates it identified and worked with issuing authorities to revoke those for Google properties. It advised domain owners to monitor certificate transparency logs and restrict which authorities can issue certificates through DNS records. Google cautioned that domain owners should not rely solely on browser interventions to protect users.

## Sources

- [Ars Technica](https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services/)

---
Canonical: https://techandbusiness.org/newswire/V3CqLgRRYleQrczxM5cAiU
Published: 2026-10-06T23:15:55.074Z
Story chronology: 2026-10-06T19:21:14.000Z
Retrieved: 2026-10-07T01:20:42.024Z
Publisher: Tech & Business (techandbusiness.org)
