Hijacked African Country Domains Let Attackers Forge Google Certificates, Testing Internet Trust
Attackers took control of the .gh, .sl and .as country registries, changed their DNS records, and obtained at least 12 unauthorized TLS certificates for Google and YouTube domains, in an incident that Google says did not breach its own systems but revealed a weak spot in the internet’s security chain.
A targeted strike on three small national web domains has exposed how attackers can tamper with the foundations of internet trust without ever touching a big tech company’s own servers.
Researchers say attackers hijacked the registries for the .gh, .sl and .as country‑code top‑level domains, which correspond to Ghana, Sierra Leone and American Samoa. With that access, they changed authoritative DNS settings and were able to obtain at least 12 unauthorized TLS certificates for Google and YouTube domains. TLS certificates are the digital credentials that tell browsers they have reached a genuine website rather than a fake one.
Google says its internal systems were not breached in this incident. According to the company, the attack did not involve compromise of its own infrastructure. Instead, the intruders went after the domain infrastructure that routes traffic to Google services. By altering DNS records under the affected country‑code domains, they were able to pass the checks that publicly trusted certificate authorities use to confirm that a certificate requestor controls a domain.
All 12 of the unauthorized certificates have been revoked, according to detailed reporting on the case. Even so, their brief existence highlights a systemic weakness. Certificate authorities often rely on DNS‑based methods to verify control of a domain. If someone can seize control of a top‑level registry or its name servers, even temporarily, that layer of validation can be fooled into endorsing impostor sites.
For ordinary users, there is usually no visible sign of this kind of attack unless the forged certificates are actively used in the wild. In a worst‑case scenario, an actor with both fake certificates and access to key network points could intercept traffic and present a browser with what appears to be a valid connection to Google or YouTube while silently reading or altering the data.
The choice of targets underlines a separate problem. Smaller country‑code registries in Africa and the Pacific often operate with more limited security resources than large commercial domains. Yet the global certificate system treats a DNS response from .gh or .sl as just as authoritative as one from .com when validating who controls a domain. That makes these registries attractive stepping stones for anyone seeking legitimate‑looking certificates tied to global brands.
For Ghana, Sierra Leone and American Samoa, the incident raises questions about the security of their national namespaces. Country‑code domains are part of a state’s digital infrastructure. When they are hijacked, the damage can extend to local businesses and public services that depend on trust in those addresses.
The core lesson from this episode is that browser padlocks and https labels reflect trust in several underlying institutions, including national registries and certificate issuers. When attackers compromise those, they can, for a time, imitate even the most familiar web services.
Signals to watch now include whether certificate authorities adjust their validation rules for high‑value domains, whether there is pressure for common minimum security standards at country‑code registries, and whether this case prompts disclosures of similar hijacks that may have gone unnoticed.
Sources
- OSINT