Attackers hijack top-level domains, obtain counterfeit TLS certificates for Google and other major services

Google says it has blocked affected certificates and updated Chrome to protect users

By LineZotpaper
Published
Read Time2 min
Attackers hijacked three country code top-level domains and used their control to mint counterfeit TLS certificates for Google and several other leading global brands, Google announced Tuesday. Google stated it has updated its Chrome browser to block all unauthorized certificates identified and worked with issuing certification authorities to revoke the fraudulent certificates for its own domains.

Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

TLS certificates are the cryptographic credentials that underpin authentication and encryption protections for websites, mail servers, and other Internet infrastructure. These x.509 certificates use a digital signature to bind a domain name such as google.com to a public key. The public key is publicly available, while the private key is held only by the website operator. When a connection shows that the keys match, the visiting party knows it’s connected to the authentic site rather than an impostor. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected infrastructure.

§

Analysis

Why This Matters

  • The breach undermines the core trust mechanism of HTTPS, potentially allowing attackers to intercept or redirect traffic to lookalike pages.
  • Google and other affected brands are central to global digital infrastructure; a successful impersonation attack could result in widespread phishing, data theft, and credential compromise.
  • The attack exploits systemic weaknesses in domain validation and certificate issuance, which may prompt industry-wide reforms.

Background

Country code top-level domains (ccTLDs) are managed by national registries under the oversight of the Internet Corporation for Assigned Names and Numbers (ICANN). Domain validation checks are a standard method used by certificate authorities to verify that an applicant controls a domain before issuing a TLS certificate. By compromising DNS records of the ccTLDs, the attackers bypassed that verification. This type of attack is rare but serious when it occurs, because it not only threatens the targeted domains but also damages confidence in the entire public key infrastructure.

Key Perspectives

Google and affected organizations: Their priority is user safety. They have acted quickly to block fraudulent certificates and revoke them, aiming to minimise the window of exposure. Certificate authorities: Issuers must balance rigorous validation against friction. They may need to review their domain validation processes and consider additional checks for high-risk domains. Security researchers: This event highlights the fragility of automated domain validation and the risks of concentrated power in ccTLD registries. Critics argue that stronger, multi-factor domain validation should be mandatory and that ccTLD security must be hardened.

What to Watch

  • Whether details emerge of any actual exploitation of the counterfeit certificates beyond their issuance.
  • How ICANN and the affected ccTLD registries respond to secure their systems.
  • Any announcements from browser vendors or the CA/Browser Forum about tightening domain validation requirements.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.