Attackers took over the systems behind three country-code internet domains last week and used that control to obtain security certificates for websites they did not own, including several Google domains. Google's Chrome team set out on 6 October 2026 what happened and what it has done about it.
The three domains are .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). According to the Chrome Secure Web and Networking Team, the attackers compromised the third-party registries that run these endings and changed the authoritative DNS records, the internet's address book entries, for domains registered under them.
Once a domain's DNS points to the attacker, the attacker can pass the routine checks that certificate authorities use to confirm who controls a domain. That is how they obtained unauthorised HTTPS certificates, the digital ID cards that make the padlock appear in a browser.
What Google says was and was not affected
Google says its own systems were not compromised at any point. It also says the certificate authorities that issued the certificates did not break the rules: they ran domain validation correctly, but the DNS answers they received had been tampered with at the registry level.
Chrome moved quickly to block the bad certificates through CRLSets, a list Chrome uses to push certificate blocks to browsers, and worked with the certificate authorities to revoke them. Google says Chrome users do not need to do anything.
The public record of certificates helped. Certificate Transparency, a system that logs publicly trusted certificates in open, append-only logs, let Chrome's team spot other organisations hit by the same attack and block those certificates before they could be used widely.
Why this matters beyond three small domains
Most people will never visit a .sl or .as website, but the attack shows a weak point that sits above any single company: the registry. A company can lock down its own servers and still be exposed if the organisation that runs the domain ending is breached. Short, memorable country endings are popular with tech firms and link shorteners, which is one reason big names had domains there in the first place.
For Indian businesses, the lesson applies to any regional or vanity domain they hold, not only to these three. Many groups keep country domains for marketing campaigns or to stop others from squatting on their brand, and those are the ones least likely to be watched.
What domain owners are asked to do
Google's first advice is to watch the Certificate Transparency logs for every domain you own, including parked and regional ones that carry no live service. Owners of domains under .gh, .sl or .as should look back at recent log entries for certificates they did not request.
The second step is to publish strict CAA records, the DNS entries that say which certificate authorities may issue certificates for a domain, and to bind them to a specific ACME account where the authority supports it. Google is frank about the limit here: during an active registry hijack, the attacker controls DNS and can change those records too. But strict CAA records help once control is restored, and they stop attackers from reusing old validation results that a certificate authority may have cached.
Security teams in India can also follow the advisories that CERT-In publishes for browsers, such as its recent high-severity warning on Chrome for desktop, and keep browsers updated so that blocks like these reach every machine.
Google's longer-term plan
Google says the episode supports changes it has already been pushing through its root programme: shorter certificate lifetimes and less reuse of old domain validation, so that a stolen or wrongly issued certificate is useful for less time. It points to the Chrome Root Program and its newer quantum-resistant root programme as the places where those rules are being set.
Ordinary users have one practical takeaway. A padlock means the connection is encrypted, not that the site is honest. Scams that copy the look of real brands, like the impersonation frauds regulators warned about this week, work best when people trust a familiar name in the address bar without checking it.








