Google reported on Tuesday, 6 October 2026, that attackers had compromised the registries for the .gh, .sl and .as country-code top-level domains. They changed authoritative DNS records and nameserver delegations for selected domains, which let them redirect traffic and pass automated domain-control checks. The attackers obtained unauthorized X.509 certificates for several Google domains and for several leading global brands and widely used online services.
TLS certificates connect a domain such as google.com to a public key. The matching private key should remain with the service operator. An unauthorized certificate can therefore support cryptographic impersonation, even when the affected organization's own infrastructure remains intact. Google said the certification authorities involved followed their required procedures.
Google has not identified the affected Google domains or named the other organizations. The company also has not disclosed how many certificates were issued or whether every non-Google certificate was blocked. Chrome now blocks all known unauthorized certificates, and Google worked with the issuing certification authorities to revoke the certificates for its own properties.
Formal certificate revocation is slow, so browser vendors can apply faster local blocks. Google said Chrome users do not need to take action, but browser protections do not cover every browser and cannot guarantee that every affected domain was found. Domain owners should check Certificate Transparency logs for unexpected issuance and publish restrictive Certification Authority Authorization records in DNS. Certificates that remain undiscovered could still be abused.
The incident follows earlier certificate failures. In 2011, attackers compromised the Netherlands-based certificate authority DigiNotar and created fraudulent certificates for Google.com and more than 200 other high-traffic domains. Those certificates were used against at least 300,000 people connected to Iran. Later cases have involved failures by certificate authorities as well as weaknesses at domain holders.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.