Jessica Entwistle
October 8 2026
The Register reports that attackers compromised three country-code top-level domain (ccTLD) registries and obtained unauthorised HTTPS certificates for several Google domains. The affected domains were .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). Google confirmed on 6 October that its own systems were not breached, but the registry-level compromise allowed attackers to manipulate DNS records and request valid certificates from trusted certificate authorities. This means an attacker could potentially impersonate legitimate Google services over encrypted connections without triggering the usual browser certificate warnings that users rely on to verify authenticity. The incident demonstrates that trust infrastructure can be subverted at levels outside the control of the domain owner.
This incident matters because it undermines one of the foundational trust mechanisms of the internet. HTTPS certificates are intended to prove that a website is genuinely operated by the organisation it claims to represent. By compromising the domain registries themselves, attackers bypassed the usual certificate issuance controls and obtained certificates that would appear legitimate to browsers and users. For UK organisations, this highlights the risk that trust infrastructure can be subverted at levels outside your direct control. It also reinforces the importance of defence in depth, including monitoring for unexpected certificate issuance, implementing certificate transparency logging, and ensuring that authentication and access controls do not rely solely on the presence of a valid certificate. Organisations that operate critical services, handle sensitive data or are frequent targets of phishing should pay particular attention to this development, as it represents a sophisticated method of bypassing user awareness and technical controls.
Review whether you monitor certificate transparency logs for your own domains, whether your security controls would detect an unexpected certificate being issued in your name, and whether your users are trained to recognise other indicators of phishing beyond the presence of a padlock icon. Consider implementing certificate pinning for critical applications, where appropriate, and ensure your DNS records are protected with DNSSEC and registry lock features where available. Check that your domain registrar accounts use strong authentication, ideally with hardware security keys, and that access is limited to a small number of authorised individuals. Review your incident response plan to ensure it includes a process for responding to fraudulent certificate issuance, including how you would identify affected users, revoke certificates, and communicate with customers and partners. Finally, ensure your security awareness training explains that a valid certificate does not guarantee a website is legitimate, and that users should verify URLs carefully, particularly when entering credentials or sensitive information.
Source: The Register