Google: Google says counterfeit TLS certificates of major services stolen by hackers

Google: Google says counterfeit TLS certificates of major services stolen by hackers

Cybercriminals Hijack Country-Code Domains to Obtain Fraudulent HTTPS Certificates

Attackers recently compromised three country-code top-level domains (ccTLDs) .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) to generate fraudulent HTTPS certificates for major websites, including Google and other high-profile organizations. By manipulating authoritative DNS records, the threat actors could intercept traffic, redirect users to malicious sites, and steal sensitive data all while displaying a legitimate padlock icon to deceive visitors.

Google confirmed the incident, stating that the certificates have since been revoked. While the company blocked the unauthorized certificates in Chrome and worked with issuing Certificate Authorities (CAs) to revoke them, it acknowledged that some affected domains may not have been fully identified, leaving users of non-Chrome browsers potentially exposed.

The attack impacted "several leading global brands and widely used online services," though Google did not disclose specific victims. The company reached out to affected organizations where possible but did not provide further details on the scale of the breach.

This incident follows a pattern of similar attacks, including the 2011 DigiNotar breach, where cybercriminals generated hundreds of fraudulent certificates for major tech companies, and a 2015 case involving Symantec’s improper issuance of unauthorized certificates.

Google emphasized its commitment to long-term security improvements, including reducing certificate validity periods and enhancing domain control validation (DCV) practices, to mitigate future risks. Chrome users were automatically protected, but domain owners were advised to monitor Certificate Transparency logs and implement restrictive CAA records.

Source: https://www.techradar.com/pro/security/google-says-counterfeit-tls-certificates-of-major-services-stolen-by-hackers

Google cybersecurity rating report: https://www.rankiteo.com/company/google

"id": "GOO1791477237",
"linkid": "google",
"type": "Cyber Attack",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Potentially millions (users of '
                                              'affected domains)',
                        'industry': 'Technology / Internet Services',
                        'location': 'Global',
                        'name': 'Google',
                        'size': 'Enterprise',
                        'type': 'Technology Company'},
                       {'location': 'Global',
                        'type': 'Other high-profile organizations'},
                       {'industry': 'Internet Infrastructure',
                        'location': 'Ghana',
                        'name': 'Ghana ccTLD (.gh)',
                        'type': 'Country-Code Top-Level Domain Registry'},
                       {'industry': 'Internet Infrastructure',
                        'location': 'Sierra Leone',
                        'name': 'Sierra Leone ccTLD (.sl)',
                        'type': 'Country-Code Top-Level Domain Registry'},
                       {'industry': 'Internet Infrastructure',
                        'location': 'American Samoa',
                        'name': 'American Samoa ccTLD (.as)',
                        'type': 'Country-Code Top-Level Domain Registry'}],
 'attack_vector': 'Manipulation of authoritative DNS records',
 'customer_advisories': 'Chrome users were automatically protected; non-Chrome '
                        'users may still be at risk if visiting affected '
                        'domains.',
 'data_breach': {'data_exfiltration': 'Possible (via traffic interception)',
                 'personally_identifiable_information': 'Possible',
                 'sensitivity_of_data': 'High (if personally identifiable or '
                                        'financial data was intercepted)',
                 'type_of_data_compromised': 'Potentially sensitive user data '
                                             '(e.g., login credentials, '
                                             'payment information)'},
 'description': 'Attackers compromised three country-code top-level domains '
                '(ccTLDs) .gh (Ghana), .sl (Sierra Leone), and .as (American '
                'Samoa) to generate fraudulent HTTPS certificates for major '
                'websites, including Google and other high-profile '
                'organizations. By manipulating authoritative DNS records, the '
                'threat actors intercepted traffic, redirected users to '
                'malicious sites, and stole sensitive data while displaying a '
                'legitimate padlock icon to deceive visitors.',
 'impact': {'brand_reputation_impact': 'High (for affected brands and ccTLD '
                                       'registries)',
            'data_compromised': 'Sensitive user data (potentially)',
            'identity_theft_risk': 'High (due to potential data theft)',
            'operational_impact': 'Traffic interception and redirection to '
                                  'malicious sites',
            'payment_information_risk': 'High (if payment data was '
                                        'intercepted)',
            'systems_affected': 'Affected ccTLDs (.gh, .sl, .as) and domains '
                                'using fraudulent HTTPS certificates'},
 'investigation_status': 'Ongoing (some affected domains may not have been '
                         'fully identified)',
 'lessons_learned': 'Need for stricter domain control validation (DCV) '
                    'practices, shorter certificate validity periods, and '
                    'proactive monitoring of Certificate Transparency logs.',
 'motivation': 'Data theft, traffic interception, financial gain',
 'post_incident_analysis': {'corrective_actions': 'Revocation of fraudulent '
                                                  'certificates, blocking in '
                                                  'Chrome, advising domain '
                                                  'owners to implement CAA '
                                                  'records, and enhancing DCV '
                                                  'practices.',
                            'root_causes': 'Weak domain control validation '
                                           '(DCV) practices, lack of '
                                           'restrictive CAA records, and '
                                           'insufficient monitoring of '
                                           'Certificate Transparency logs.'},
 'recommendations': 'Implement restrictive CAA records, monitor Certificate '
                    'Transparency logs, reduce certificate validity periods, '
                    'enhance DCV practices, and educate users on risks of '
                    'fraudulent certificates.',
 'references': [{'source': 'Google'}],
 'response': {'communication_strategy': 'Public disclosure by Google, '
                                        'advisories to affected organizations '
                                        'where possible',
              'containment_measures': 'Fraudulent certificates revoked, '
                                      'blocked in Chrome',
              'enhanced_monitoring': 'Monitoring of Certificate Transparency '
                                     'logs recommended',
              'remediation_measures': 'Worked with Certificate Authorities '
                                      '(CAs) to revoke certificates, advised '
                                      'domain owners to monitor Certificate '
                                      'Transparency logs and implement '
                                      'restrictive CAA records'},
 'stakeholder_advisories': 'Affected organizations were contacted where '
                           'possible; domain owners advised to monitor logs '
                           'and implement CAA records.',
 'title': 'Cybercriminals Hijack Country-Code Domains to Obtain Fraudulent '
          'HTTPS Certificates',
 'type': 'DNS Hijacking / Certificate Fraud',
 'vulnerability_exploited': 'Weak domain control validation (DCV) practices'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.