# Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

> **Open Intelligence Dossier** · First detected: 2026-10-09 09:40 UTC · Category: Technology

## Executive Summary
Attackers hijacked country-code domains to impersonate Google and other major services, creating security risks.

## Intelligence Brief
Recent reporting details a security incident involving the hijacking of country-code top-level domains. According to coverage from Malwarebytes, attackers successfully seized these domain designations to impersonate Google and other unspecified organizations and services. The activity centers on the exploitation of top-level domains to facilitate fraudulent activities and unauthorized impersonation across the digital landscape.


Context provided within the reporting indicates that domain hijacking and the unauthorized generation of security certificates represent significant threats to internet infrastructure and user trust. While the coverage does not yet specify the full list of impacted organizations beyond Google, the technique targets the foundational trust mechanisms of the web. Security certificates are designed to verify the identity of websites, making their unauthorized minting a critical development for online security analysts.


Future updates will depend on further disclosures from security researchers and affected entities. Coverage does not yet specify whether the attackers have been identified, nor does it detail the total volume of users affected by the fraudulent certificates. Observers will need to monitor ongoing reports from Malwarebytes and other security organizations to track potential mitigations or responses from domain registries and impacted service providers.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| Malwarebytes | Attackers hijack country-code domains to impersonate Google and other services | [Source Link](https://news.google.com/rss/articles/CBMiwwFBVV95cUxQeEtGbnpuOXNDeldtNDdOcWdjMGdwRUlWTjYweTlua1hRM21rbXhoV0NEQ21CbU0zSGstckhCek1HOUlfZE9Id29UY3JqLUhYd2RiU0ZhUjFlMTF0dG80bnpONFJBZVVVRVRoLWRGNUxjcURIRGZlaHFSQWZjWHlHdGxYUmg4LXg4TS1GQkc0M2ZyNU1CX3RPdk5wQ0w3YzRRV2VCQzZRa2sxbmtJdk5jMnYtNHJsVnpfaEhFS090RUd3dzQ?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-10-09/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and*
