HOC Shorts
Cybercriminals compromised the infrastructure of three Country-Code Top-Level Domain (ccTLD) registry—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa).
- The Impact: Attackers modified authoritative DNS records to pass Domain Control Validation (DCV) and trick legitimate Certificate Authorities (Let’s Encrypt and ZeroSSL) into issuing 12 rogue SSL/TLS certificates for high-value domains like `google.sl`, `google.as`, and `google.com.gh`.
- Google’s Status: Google confirmed no internal systems were breached.
- Chrome’s Action: Google Chrome deployed emergency CRLSets to block the unauthorized certificates instantly, forcing Certificate Authorities to revoke them.
- Key Takeaway: Traditional security like DNSSEC or CAA records cannot completely stop a full registry-level hijack, making continuous Certificate Transparency (CT) log monitoring vital for all domain owners.
Google’s Chrome Secure Web and Networking Team issued an urgent security report addressing a cyber attack against regional country-code internet registries. Threat actors briefly took control of registry infrastructure supporting three countries—Ghana (`.gh`), Sierra Leone (`.sl`), and American Samoa (`.as`)—to create fraudulent SSL certificates for Google and YouTube web properties.
This incident highlights how hackers can bypass traditional website security controls by attacking the core domain registries that govern the internet itself.
How the ccTLD Registry Attack Happened

1. Registry Infrastructure Breach: Threat actors compromised the backend infrastructure managing the `.gh`, `.sl`, and `.as` domain extensions.
2. DNS Record Manipulation: The attackers altered the authoritative Name Server (NS) delegation records for domains like `google.sl`, pointing web queries toward attacker-controlled servers.
3. Deceiving Certificate Authorities: Certificate Authorities (CAs) like Let’s Encrypt use automated DNS checks to verify domain ownership. Because the registry itself was compromised, the attackers successfully proved “ownership” and tricked CAs into issuing 12 valid TLS certificates for Google and YouTube subdomains.
4. Traffic Interception Risk: Armed with a valid SSL certificate and controlled DNS, an attacker could theoretically perform Man-in-the-Middle (MitM) attacks, listening to encrypted user communications without triggering browser warnings.
Chrome’s Rapid Security Response
Google clarified that its internal infrastructure was never penetrated or breached. The Chrome security team deployed push-based countermeasures to shield users globally:
- Emergency Blocking via CRLSets: Chrome instantly pushed updated CRLSets (Chrome’s certificate revocation lists) directly to user browsers, blocking the rogue certificates before they could be weaponized.
- Forced Revocation: Google worked alongside the issuing Certificate Authorities to immediately revoke all 12 fraudulent certificates.
- Cross-Organization Threat Hunting: Using Certificate Transparency (CT) logs, Google identified additional non-Google domain certificates generated in the same attack wave and alerted affected domain operators.
Why CAA and DNSSEC Couldn’t Stop the Hack
A critical lesson from this incident is why traditional defensive tools failed to prevent certificate creation:
| Security Protocol | Standard Function | Why It Failed in This Hijack |
| Certification Authority Authorization (CAA) | Restricts which CAs can issue certificates for your domain. | Because the registry was compromised, attackers answered DNS queries and modified CAA rules on-the-fly. |
| DNSSEC (DNS Security Extensions) | Digitally signs DNS data to prove authenticity. | The registry holds the master signing keys (DS records). Hijacking the registry allows attackers to sign false records legitimately. |
| Multi-Perspective Validation | CAs check DNS from multiple global locations to prevent localized hijacking. | A ccTLD registry hijack is global; every server worldwide receives the same manipulated DNS responses. |
Action Plan for Website Owners & System Admins
To safeguard your organization’s domain portfolio against top-tier registry compromises, Google recommends implementing the following defense-in-depth steps:
1. Monitor Certificate Transparency (CT) Logs: Set up real-time CT log monitoring for your primary, defensive, regional, and parked domains to get instant alerts whenever any CA issues a certificate for your brand.
2. Monitor TLD Name Servers Directly: Run automated scripts that query the parent ccTLD registry directly for your domain’s delegation records. If the registry’s Name Servers suddenly point away from your official DNS provider, trigger immediate incident response playbooks.
3. Use CAA with ACME Account Binding: Implement strict CAA records bound directly to your specific Certificate Authority account IDs. While it cannot stop a live DNS hijack, it prevents attackers from using automated public tools once DNS control is restored.