Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Trusted brand impersonation without the usual browser certificate warnings spells trouble
Hackers have seized control of key internet addresses, creating fake security certificates for major companies like Google and others. By manipulating DNS records, they minted fraudulent HTTPS certificates for domains belonging to Google and other organizations in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs).
Google detected the attacks last week and warned of the hijacks, stating that the certificates were obtained without authorization. The fraudulent certs did not compromise Google's systems directly. However, they allow attackers to impersonate legitimate sites, potentially intercepting or modifying data sent by users and distributing malware or phishing schemes.
Google acknowledged that browser interventions, such as Chrome blocking suspected counterfeit certificates, are necessary but not foolproof for protecting users across all devices. To safeguard their domains, Google advises organizations to monitor Certificate Transparency logs for any suspicious certificates issued for their domains.
They also suggest using restrictive Certification Authority Authorization records to control which Certificate Authorities can issue certificates for their domains, helping protect domains once DNS control is restored.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.