Hackers Forge Google TLS Certificates by Hijacking Country Domains
Hackers have exploited a critical vulnerability in the domain validation system used by certificate authorities, allowing them to forge real, trusted TLS certificates for major services like Google. The attackers compromised three country-code top-level domain (ccTLD) registries, controlling the .gh (Ghana).sl (Sierra Leone), and .as (American Samoa) domains, and altered DNS records to pass automated validation checks. This enabled them to obtain legitimate certificates from certificate authorities, which were trusted by major browsers.
Google confirmed it updated Chrome to block the counterfeit certificates and coordinated with other browser makers and certificate authorities to do the same. However, the company acknowledged it cannot guarantee it has identified every unauthorized certificate issued through this method. This oversight poses significant risks for banks, crypto exchanges, and enterprise SaaS platforms, as forged certificates could enable man-in-the-middle attacks on sensitive transactions.
The incident highlights a longstanding weakness in the domain validation process, which only verifies control of a domain at the moment of the check. If a ccTLD registry is compromised, every domain under that extension becomes vulnerable, as certificate authorities have no way to distinguish between legitimate and malicious DNS record changes. Past incidents, such as the 2011 DigiNotar breach and the Sea Turtle campaign, demonstrate the persistent threat posed by compromised registries.
Google has advised domain owners to actively monitor Certificate Transparency logs to detect unauthorized certificates. The company’s guidance reflects a shift away from relying solely on certificate authorities to prevent fraud. The underlying issue remains unaddressed by the certificate authority ecosystem, leaving every ccTLD registry a potential single point of failure for the TLS trust chain.