Skip to content
Hackers Acquire Counterfeit TLS Certificates via ccTLD Hijacks

Hackers Acquire Counterfeit TLS Certificates via ccTLD Hijacks

First seen 6 Oct 2026, 21:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 22:57 UTC
  • •Hackers hijacked ccTLDs to obtain unauthorized TLS certificates.
  • •Google confirmed no compromise of its systems or those of affected domain owners.
  • •Chrome has blocked the unauthorized certificates, but the scope of impact is still being assessed.

On October 6, 2026, Google reported that hackers obtained unauthorized TLS certificates through the hijacking of ccTLDs (.gh, .sl, .as). The attackers modified DNS records to gain control over these domains, allowing them to issue certificates for various Google and other organizations' domains. Google stated that this incident did not compromise their infrastructure or that of the affected domain owners. Although Chrome has blocked the unauthorized certificates, the full extent of the impact remains unclear, with additional organizations potentially affected. The certificates were issued without the Certification Authorities (CAs) being at fault. The incident echoes previous events, such as the 2011 DigiNotar breach, highlighting ongoing vulnerabilities in certificate issuance processes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-06
Google reports TLS certificate hijacking
Google disclosed that hackers obtained unauthorized TLS certificates via ccTLD hijacks affecting multiple domains.
Arstechnica
2026-10-06
Chrome blocks unauthorized certificates
Chrome's Secure Web and Networking Team blocked unauthorized HTTPS certificates to protect users following the ccTLD hijacks.
blog.google

More articles in this cluster (2)

Following this threat?

Track DigiNotar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What domains are affected?
Domains ending in .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) are at risk.
Are the unauthorized certificates still valid?
No, Google has blocked the unauthorized certificates in Chrome, and efforts are underway to revoke them.
What should organizations do now?
Organizations should verify their TLS certificates and monitor for any unauthorized certificates issued under their domains.