Hackers compromised ccTLD registries for Ghana, American Samoa, and Sierra Leone, obtaining unauthorized HTTPS certificates for Google domains and other organizations by modifying DNS records. Google blocked the certificates in Chrome via CRLSets and worked with Certificate Authorities to revoke them, warning that other browsers may lack protection and some affected domains may remain unidentified.
Attackers compromised three country-code top-level domains (.gh, .sl, .as) and obtained unauthorized HTTPS certificates for Google and YouTube domains in late September. Google blocked the certificates through Chrome's CRLSets and worked with certificate authorities to revoke them, though the attack also affected other organizations and the longest gap between certificate issuance and revocation was nearly a week.