{
  "id": 12735056,
  "title": "Attackers hijacked top-level domains, minted fake security certs for Google and other orgs",
  "url": "https://urgent.news/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T19:38:06.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and-other-orgs/5301718"
  },
  "original_language": "en",
  "account": "Hackers have taken control of key website addresses, creating fake versions of Google and other well-known sites. Attackers manipulated the internet's domain name system (DNS) records and created fake security certificates for several Google domains and those of other organizations. The attacks occurred in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level domains. Google was alerted to the incidents last week.\n\nDuring the hijacks, the cybercriminals altered the authoritative DNS records and obtained unauthorized HTTPS certificates covering Google domains and domains of other organizations. However, Google's systems remained unaffected, and Chrome swiftly blocked suspected counterfeit certificates for the affected ccTLDs, ensuring protection for Chrome users.\n\nThe attackers can now impersonate legitimate organizations and websites without triggering browser security alerts, enabling them to intercept or modify data sent by users to the impersonated sites. This could allow them to distribute malware or launch phishing attacks, abusing the trusted organization's brand.\n\nGoogle advises domain owners to monitor Certificate Transparency (CT) logs for their domains, including parked or regional ccTLD properties, to identify unauthorized certificates in near real-time. If an organization operates a domain in .gh, .sl, or .as, they should review recent CT log entries for any unexpected certificates. Additionally, organizations can publish restrictive Certification Authority Authorization (CAA) DNS records, limiting certificate issuance to specific authorized accounts and validation methods, preventing attackers from minting new certificates after a hijacking ends.",
  "summary": "Trusted brand impersonation without the usual browser certificate warnings spells trouble",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Attackers hijacked top-level domains, minted fake security certs for Google and other orgs",
        "url": "https://urgent.news/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-12737292",
        "published": "2026-10-07T19:38:06.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}