Attackers hijack country-code domains to impersonate Google and other services

| October 8, 2026
pointing in the wrong direction

According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. These domain endings aren’t limited to sites serving those countries, so the risk can extend to users elsewhere.

This wasn’t a break in encryption, and Google’s systems weren’t compromised. Instead, attackers manipulated the internet’s addressing infrastructure so they could pass the checks required to obtain certificates for domains they didn’t legitimately control.

The Domain Name System (DNS) helps direct internet traffic to the right destination. Control over DNS can also provide a way to demonstrate apparent control of a domain when requesting an HTTPS certificate.

An HTTPS certificate helps a browser authenticate the server it is connecting to. A trusted certificate authority issues the certificate after checking that the applicant controls the relevant domain.

By controlling DNS records, attackers can pass domain verification checks. The authority can then issue a genuine, signed certificate to someone who has hijacked the domain’s infrastructure.

Combined with the ability to redirect a victim’s traffic to an attacker-controlled server, that could enable cybercriminals to create a convincing impersonation of the real service.

Google initially blocked unauthorized certificates for its own properties in Chrome and worked with the issuing certificate authorities to revoke them. It later blocked suspicious certificates for other organizations in Chrome, too.

How to stay safe

Google points out that its actions do not offer complete protection:

“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.”

At the base level, this is an infrastructure problem that requires an infrastructure-level response. But these precautions can help:

  • Keep your browser and operating system updated. Install available updates so you receive the latest security fixes.
  • Don’t bypass certificate or secure-connection warnings. If your browser reports a certificate problem, stop rather than force the page to load.
  • If a service you use has an address ending in .gh, .sl, or .as, check for security notices from the provider before logging in, making payments, or sharing sensitive information.
  • Don’t treat HTTPS as an all-clear. An encrypted connection—even at the correct address—doesn’t guarantee you’re connected to the legitimate service if attackers have hijacked its DNS and obtained a valid certificate.
  • Be cautious with unexpected or unusual requests, even if they appear to come from a service you trust. Before acting, verify the request through a separate, trusted channel, not through links or contact details provided in the request itself.

These precautions are not a complete defense. The lasting fix depends on domain operators restoring control, preventing further unauthorized certificates from being issued, and ensuring existing ones are revoked or blocked.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

About the author

Pieter Arntz

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.