TECHNOLOGY · VERIFIED DEVELOPMENT
Hackers Obtain Counterfeit TLS Certificates for Google and Other Large Services
WHY IT MATTERS
This attack highlights the vulnerability of the TLS certificate issuance process, which relies on the integrity of top-level domains and DNS records. The incident underscores the need for robust security measures to prevent unauthorized certificate issuance and protect online infrastructure.
What happened
Attackers hijacked three top-level domains, . gh, .
sl, and . as, and used their control to mint counterfeit TLS certificates for Google and other large organizations.
The attackers modified authoritative DNS records for selected domains within those namespaces, allowing them to pass automated domain control validation checks. Google updated Chrome to block all identified unauthorized certificates and worked with certification authorities to revoke the unauthorized certificates for Google properties.
PRIMARY SOURCES
Hackers obtain counterfeit TLS certificates for Google and other large services
Ars Technica · Dan Goodin · Discovery only; Condé Nast copyright terms apply
CORRECTIONS & UPDATES
- Revision 1 · Initial ingestion · Oct 6, 2026, 10:15 PM
- Revision 2 · Source update detected · Oct 6, 2026, 10:15 PM