Key facts
- Hackers compromised three top-level domains (.gh, .sl, and .as) to issue counterfeit TLS certificates.
- The counterfeit certificates were issued for Google domains and other major global brands.
- Google updated Chrome to block all identified counterfeit certificates.
- The incident did not involve the compromise of the infrastructure of affected domain owners or DNS operators.
Attackers have successfully obtained counterfeit Transport Layer Security (TLS) certificates for Google and other major organizations by compromising three top-level domains. The attackers gained control of the .gh, .sl, and .as country code top-level domains (ccTLDs) and then manipulated DNS records for selected domains within these registries. This control allowed them to mint unauthorized certificates for several Google domains and other leading global brands and widely used online services.
Google stated that it has updated its Chrome browser to block all certificates identified as counterfeit and has worked with other certificate authorities to ensure other browsers implemented similar protections. The company is advising domain owners to review TLS transparency logs for any unauthorized certificates issued for their domains.

