Google says hackers have stolen counterfeit TLS certificates from major services


  • Attackers hijacked three country code domains to obtain fraudulent HTTPS certificates for major websites
  • Fake certificates could allow convincing interception of traffic and phishing against affected domains
  • Google revoked certificates, protected Chrome users and warned affected organizations

Recently, cybercriminals managed to hijack three country code top-level domains (ccTLDs) and used the access to generate HTTPS certificates covering several Google domains, as well as those belonging to other organizations. Google said the attack put thousands of websites at risk, but noted that the certificates have since been revoked.

According to Google, the hijacked domains are .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). During the attacks, threat actors modified authoritative DNS records and obtained HTTPS certificates covering not only Google, but other organizations as well.

Avatar photo

Miraj Islam is a writer and contributor at Oalanbrado, interested in news, current events, technology, lifestyle, and stories that matter to readers. He enjoys researching different topics and turning information into clear, useful, and engaging articles. Through his work, Miraj aims to keep readers informed with fresh perspectives and easy-to-understand content from Brazil and around the world.

Post Comment