Attackers compromised three country-code top-level domains (.gh, .sl, .as) and obtained unauthorized HTTPS certificates for Google and YouTube domains in late September. Google blocked the certificates through Chrome's CRLSets and worked with certificate authorities to revoke them, though the attack also affected other organizations and the longest gap between certificate issuance and revocation was nearly a week.