# Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

> **Open Intelligence Dossier** · First detected: 2026-10-08 13:40 UTC · Category: Technology

## Executive Summary
Attackers hijack country-code top-level domains to obtain unauthorized HTTPS certificates for Google, prompting direct response actions.

## Intelligence Brief
Recent technology reporting outlines a significant cybersecurity incident involving domain name system operations across multiple country-code top-level domains. The primary consequence of these registry compromises was the generation of unauthorized security certificates affecting major online properties. Media outlets have placed a strong emphasis on the scale of the digital infrastructure breach and the immediate reaction from major technology corporations. Forbes specifically reports that Google took prompt action to block the compromised Chrome security certificates following the domain attacks.


Techzine Global adds further context by explicitly confirming that hackers managed to acquire HTTPS certificates specifically targeting Google. This incident highlights ongoing vulnerabilities within global domain name system registries and the cascading trust issues that arise when country-code top-level domain infrastructure is compromised. Because modern web browsers rely on these certificates to establish secure, encrypted connections and verify website authenticity, unauthorized certificate acquisition represents a severe threat to web traffic integrity and user data security. As the situation continues to develop, ongoing coverage does not yet specify the full identity of the attackers or the complete list of all potentially impacted domains beyond Google.


Observers and stakeholders will be monitoring further technical disclosures from registry operators, security researchers, and browser vendors regarding the permanent revocation status of the affected certificates. Additional updates from the outlets currently tracking the story are expected to clarify whether other major technology entities or global websites experienced similar compromises stemming from the ccTLD hijacks.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| CircleID | DNS Hijacks Across Three ccTLDs Linked to 32 Unauthorized HTTPS Certificates | [Source Link](https://news.google.com/rss/articles/CBMipgFBVV95cUxQYV95UnlXUzlYazh5UGpVRE5VWHZWVENqSHNkb3VEdG5nX1F0bF9BQ1Y1NVJENWctcWpiR2d5Y2N5OVhGdE1HbWRWTDVvaGo5QTNuTWFLQlFVOUdjam9UUWlNQzNlZUdQTVRRM0FDSE9adDhRb0t4S1JLMEk2OVFTVVo0Rm0tZ0xKcmM2MWkwN3pMSDQ0OFczRkxMSEtleWRzX2RqSXpR?oc=5) |
| Forbes | Google Acts To Block Chrome Security Certificates After Domain Attacks | [Source Link](https://news.google.com/rss/articles/CBMiwAFBVV95cUxQUzhjcElzODNaNWp0UkYxekZoaE1fcEpWRV81bGdXdEhFZ2lVQTZWR0dUaks3dzg4ZWxkZGEzdUxZeExjVmNFT3l0WXpmNXRPX1dfZ2lUWUFZTVg5NUVLd200UTR2OUQ1NUdVNHZsaHBEY3NheS1vUl9pMTVmLWtFVk9Vcmhla3RndkMtbUhCdGxOSk1DZkZObmNBdG1UODhWLUdNX3F0ZUktdG9iZ1N4Z0dXeHVDVjVsTDd5anNYNzM?oc=5) |
| Techzine Global | Hackers obtain HTTPS certificates for Google | [Source Link](https://news.google.com/rss/articles/CBMilAFBVV95cUxQVkprQUNVY1Fnd0tKRGU3bF9yZmhIblI3NFhLT3FqOHNHeXhqeWVFVEdDQUw2eDlraEs3QmtBeHVTcXlCQ29Oei1NeUJ1UEh3V1A5cjMyZzFkVk9oQ0R5bVFtYkM2MG1jRmxCcng4cFBob1k5R3VaWl9Rb0lzdHd0eHplSnR2SUpZeEtzTW1CTXd2Z2Mz?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-10-08/attackers-hijack-gh-sl-and-as-registries-to-obtain-certificates-for-google*
