# Registry breaches let attackers hijack domains and obtain HTTPS certificates

_Published Wednesday, October 7, 2026 at 10:52 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Registry breaches let attackers hijack domains and obtain HTTPS certificates — Primary](https://www.bleepstatic.com/content/hl-images/2023/12/29/google-flare.jpg)

Attackers compromised third-party operators for Ghana's .GH, Sierra Leone's .SL and American Samoa's .AS domains, changed authoritative DNS records and obtained unauthorized HTTPS certificates, BleepingComputer reported. Google domains and other organizations were affected. Control of those records let attackers redirect visitors to their own infrastructure and impersonate legitimate brands.

Google blocked unauthorized certificates in Chrome and worked with certificate authorities to revoke them. It also identified and blocked additional certificates through public Certificate Transparency logs. Google says its own systems were not compromised and it has no reason to believe certificate authorities acted improperly. Its analysis may have missed affected domains, and Chrome's blocking mechanism does not reliably protect users of other browsers.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/)

---
Canonical: https://techandbusiness.org/newswire/ZTIy8ZBI2rBKiVmwnRn_zo
Published: 2026-10-08T02:52:30.504Z
Story chronology: 2026-10-07T20:50:13.000Z
Retrieved: 2026-10-08T05:44:25.709Z
Publisher: Tech & Business (techandbusiness.org)
