DNS hijacks across three ccTLDs linked to 32 unauthorised HTTPS certificates
An analysis of Certificate Transparency logs identified 32 unauthorised HTTPS certificates linked to DNS hijacks affecting Ghana, Sierra Leone and American Samoa. The incidents show how control over domain name records can undermine website authentication.
Attackers obtained 32 unauthorised HTTPS certificates after compromising DNS records in three country-code top-level domains (ccTLDs), according to an analysis published on 8 October. The certificates were issued between 22 and 27 September and covered domains associated with Google and other major technology organisations.
The analysis, reported by iTnews, compared public Certificate Transparency (CT) logs with Chrome’s certificate blocklist. It identified incidents involving Ghana’s .gh domain, Sierra Leone’s .sl and American Samoa’s .as. The reported sequence began with Ghana on 22 September, followed by Sierra Leone on 25 September and American Samoa on 27 September. Most certificates linked to each incident were issued within around 90 minutes.
The certificates reportedly included wildcard certificates issued by Let’s Encrypt and Sectigo’s ZeroSSL service, as well as one issued through Cloudflare’s certificate authority. The reported total has not been independently reproduced.
Google confirmed on 6 October that attackers had altered authoritative DNS records in the three namespaces to obtain certificates for Google domains and domains belonging to other organisations. It said its own systems had not been compromised and that there was no reason to believe the certificate authorities had acted improperly.
The attacks exploited the link between DNS control and certificate issuance. Certificate authorities use domain-control checks to establish whether an applicant is authorised to obtain a certificate. If attackers can manipulate the DNS records used for these checks, they may be able to pass validation without the legitimate domain owner’s permission.
Google responded by using Chrome’s CRLSet mechanism to block the affected certificates and working with certificate authorities on revocation. It also used Certificate Transparency monitoring to identify other potentially affected organisations and extended its blocking measures. The certificates have since reportedly been revoked.
However, browser-level blocking does not necessarily protect users of every browser or application. If attackers can also redirect website traffic, an unauthorised certificate could help them impersonate a legitimate website.
Google advised domain owners to monitor Certificate Transparency logs across their domain portfolios, including parked domains and regional registrations. It also recommended restrictive Certification Authority Authorization (CAA) records and account-specific controls. CAA records can limit which certificate authorities may issue certificates for a domain, although they may not prevent issuance during an active DNS hijack.
The precise methods used to compromise the three ccTLD namespaces remain undisclosed. The public record also does not establish the full list of affected domains or whether, and to what extent, attackers intercepted user traffic.
The incidents highlight a security risk beyond individual websites: the integrity of DNS infrastructure is a key part of the trust that HTTPS relies on. Monitoring certificate issuance can help identify suspicious activity, but it does not replace the need to secure the registry and DNS systems on which domain ownership checks depend.
