Google disclosed that attackers hijacked three country-code top-level domains—.gh, .sl, and .as—and used that control to modify authoritative DNS records for selected domains. This let them pass automated domain control validation checks and obtain unauthorized TLS certificates for several Google domains as well as other large organizations and widely used online services. Google did not name the affected Google properties or the other organizations involved.
TLS certificates are meant to prove that a site is authentic by binding a domain name to a public key. Possession of unauthorized certificates allows attackers to cryptographically impersonate the affected services. Google said it updated Chrome to block all certificates it identified as unauthorized and worked with certificate authorities to revoke those tied to Google properties. The company cautioned that browser-side fixes should not be the only defense, since its analysis may have missed some affected domains and non-Chrome users are not protected by its interventions.
Google noted that the incident did not involve compromise of the affected domain owners' infrastructure, and that certificate authorities followed all requirements. The company advised domain owners to watch certificate transparency logs for unexpected issuance and to publish restrictive Certification Authority Authorization DNS records. The full scope—how many certificates were issued and whether all non-Google ones have been blocked—remains unclear. The article draws a parallel to the 2011 DigiNotar breach, where attackers minted counterfeit certificates for Google and more than 200 domains, but notes that the current incident is distinct in method and details.