Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic... The key weakness was trusting proof of control over a domain name: whoever could manipulate the...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did attackers gain control of the .gh, .sl and .as country-code domain registries and use DNS changes to obtain unauthorized TLS certifi. Article summary: The attackers compromised third-party infrastructure for the .gh, .sl and .as country-code domains, then changed DNS information for selected names. That made certificate authorities see the attackers as controlling thos. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Attackers compromised third-party infrastructure for the .gh, .sl and .as country-code domains, then changed authoritative DNS records for selected names. That let them pass certificate authorities’ domain-control checks and obtain unauthorized HTTPS certificates for several Google domains and other organizations. Google said its own systems were not compromised. The public reporting does not establish how the attackers first gained access to the domain infrastructure. 1
4
Certificate authorities (CAs) check that an applicant can demonstrate control of a domain before issuing a certificate. In this incident, control of the affected domain infrastructure let the attackers change authoritative DNS information and satisfy those checks for selected names. The reporting confirms the DNS changes and successful validation, but does not specify the exact validation method used for each certificate. 1
4
This was an abuse of the domain-control evidence used in certificate issuance, not a break of TLS cryptography. The attackers did not need to compromise the affected service’s website to make the CA’s check succeed: control over the relevant DNS records could be enough. 4
Google identified the affected country-code namespaces as .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), and said unauthorized certificates covered several Google domains and domains belonging to other organizations. It said Google’s systems were not compromised. 1
The public account does not identify the attackers’ initial access method or provide a complete list of affected organizations and certificates. Certificate issuance alone also does not establish that attackers intercepted users’ traffic. 1
4
Google said it blocked the unauthorized certificates it identified in Chrome and worked with certificate authorities on revocation. Blocking identified certificates is a mitigation, not proof that every unauthorized certificate has been found or that every user is protected. 1
16
Owners of domains under affected suffixes should verify their registry access, nameserver delegations and authoritative DNS records. They can also review Certificate Transparency logs for certificates they did not authorize; an unexpected certificate warrants investigation and contact with the relevant registrar, registry and certificate authority. 16
The DigiNotar incident involved a different point of failure: attackers compromised a certificate authority and obtained a fraudulent Google certificate, which was used in attacks on users in Iran. In the .gh, .sl and .as incidents, attackers manipulated domain infrastructure to pass certificate checks rather than compromising the CA itself. 21
Sea Turtle is a closer DNS-side comparison. That campaign involved hijacking domain-management infrastructure to alter DNS and redirect visitors; it illustrates how control of DNS can be used to undermine trust in a site’s identity. 28
The available sources do not provide enough verifiable detail about the separate google.tg case to compare its mechanics confidently with these incidents. The broader lesson is that a certificate can be correctly signed by a trusted CA and still be unauthorized if an attacker has taken control of the evidence used to prove domain ownership.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic...
Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic... The key weakness was trusting proof of control over a domain name: whoever could manipulate the relevant DNS information could satisfy certificate checks without breaking into the real website.
Google blocked certificates it identified and coordinated revocation; domain owners should check registry and DNS settings and monitor Certificate Transparency logs for unexpected certificates.
Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic... The key weakness was trusting proof of control over a domain name: whoever could manipulate the...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did attackers gain control of the .gh, .sl and .as country-code domain registries and use DNS changes to obtain unauthorized TLS certifi. Article summary: The attackers compromised third-party infrastructure for the .gh, .sl and .as country-code domains, then changed DNS information for selected names. That made certificate authorities see the attackers as controlling thos. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Attackers compromised third-party infrastructure for the .gh, .sl and .as country-code domains, then changed authoritative DNS records for selected names. That let them pass certificate authorities’ domain-control checks and obtain unauthorized HTTPS certificates for several Google domains and other organizations. Google said its own systems were not compromised. The public reporting does not establish how the attackers first gained access to the domain infrastructure. 1
4
Certificate authorities (CAs) check that an applicant can demonstrate control of a domain before issuing a certificate. In this incident, control of the affected domain infrastructure let the attackers change authoritative DNS information and satisfy those checks for selected names. The reporting confirms the DNS changes and successful validation, but does not specify the exact validation method used for each certificate. 1
4
This was an abuse of the domain-control evidence used in certificate issuance, not a break of TLS cryptography. The attackers did not need to compromise the affected service’s website to make the CA’s check succeed: control over the relevant DNS records could be enough. 4
Google identified the affected country-code namespaces as .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), and said unauthorized certificates covered several Google domains and domains belonging to other organizations. It said Google’s systems were not compromised. 1
The public account does not identify the attackers’ initial access method or provide a complete list of affected organizations and certificates. Certificate issuance alone also does not establish that attackers intercepted users’ traffic. 1
4
Google said it blocked the unauthorized certificates it identified in Chrome and worked with certificate authorities on revocation. Blocking identified certificates is a mitigation, not proof that every unauthorized certificate has been found or that every user is protected. 1
16
Owners of domains under affected suffixes should verify their registry access, nameserver delegations and authoritative DNS records. They can also review Certificate Transparency logs for certificates they did not authorize; an unexpected certificate warrants investigation and contact with the relevant registrar, registry and certificate authority. 16
The DigiNotar incident involved a different point of failure: attackers compromised a certificate authority and obtained a fraudulent Google certificate, which was used in attacks on users in Iran. In the .gh, .sl and .as incidents, attackers manipulated domain infrastructure to pass certificate checks rather than compromising the CA itself. 21
Sea Turtle is a closer DNS-side comparison. That campaign involved hijacking domain-management infrastructure to alter DNS and redirect visitors; it illustrates how control of DNS can be used to undermine trust in a site’s identity. 28
The available sources do not provide enough verifiable detail about the separate google.tg case to compare its mechanics confidently with these incidents. The broader lesson is that a certificate can be correctly signed by a trusted CA and still be unauthorized if an attacker has taken control of the evidence used to prove domain ownership.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic...
Attackers compromised third party infrastructure for .gh, .sl and .as and changed authoritative DNS records, allowing them to pass domain control checks and obtain unauthorized certificates for Google and other servic... The key weakness was trusting proof of control over a domain name: whoever could manipulate the relevant DNS information could satisfy certificate checks without breaking into the real website.
Google blocked certificates it identified and coordinated revocation; domain owners should check registry and DNS settings and monitor Certificate Transparency logs for unexpected certificates.