On October 6, 2026, Google's Chrome team disclosed that attackers had compromised the country-code registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as). They changed authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains and other organizations' domains. Google says its own systems were not breached, and it has no reason to believe the issuing certificate authorities did anything wrong. Chrome blocked the Google certificates through CRLSets, used Certificate Transparency logs to find other affected organizations and block their certificates, and worked with the CAs on revocation so other browsers were covered too (Google).
The attack worked because the system behaved as designed
A public CA issuing a certificate through domain validation is checking one thing: whether the applicant controls the domain's DNS at that moment. An attacker who controls the registry controls that answer. As Startup Fortune put it, the CA "has no way to know the difference" between legitimate and fraudulent DNS control, so every domain under a compromised extension is only as trustworthy as the attacker allows (Startup Fortune). That piece also notes the weakness is not new. A Let's Encrypt certificate was once issued for google.tg after Togo's registry was compromised.
The incident therefore does not show careless CAs. It shows that the web's trust model has a structural dependency: roughly 250 country registries, run with very different security budgets, sit upstream of every certificate issued under their names.
The case for stricter control
The strongest argument for tighter regulation is that the risk is systemic and the party that bears it is not the party that controls it. A small registry in a small economy can be the entry point to attacks on global brands. Mandatory security standards, audits or even licensing of registry operators would, on this view, be proportionate to a risk that crosses borders. The argument deserves a serious answer.
Why mandates are the wrong tool
The answer is that the layers that actually worked in this incident were voluntary, technical and fast. Chrome acted within days of learning of the hijacks, and Certificate Transparency logs let the team find victims it had never been told about. Google's recommendations to domain owners are practical. Monitor CT logs, which "provides a near real-time alert whenever a certificate is issued", and publish CAA records with account bindings to restrict which CAs can issue (Google).
A licensing regime would be slow, would be applied unevenly across jurisdictions, and would invite governments to treat registry oversight as a lever over domain content. Anyone who values an open, single, interoperable internet should be wary of that. The ccTLD model works because operators answer to local communities, and a global compliance layer would weaken it. It would also not stop a determined intruder.
The existing hardening is real but incomplete
The CA/Browser Forum has already tightened validation. Its Baseline Requirements made Multi-Perspective Issuance Corroboration mandatory from March 15, 2025. CAs must corroborate domain validation and CAA results from multiple network perspectives. DNSSEC validation became mandatory for the primary network perspective from March 15, 2026 (CA/Browser Forum).
Those controls defend well against attacks on the network path, such as BGP hijacks that mislead a single validation vantage point. They are weaker against this incident. If an attacker controls the registry's authoritative data, every perspective sees the same altered answer. DNSSEC authenticates that data came from the zone and was not modified in transit (ICANN), but a compromised registry can potentially change delegation and signing data at the source. This is analysis, not something the disclosures have confirmed. Google's post, for its part, does not discuss DNSSEC or multi-perspective validation. We do not yet know how the registries were breached or how long the attackers had access, and any policy conclusion should wait for that.
What proportionate response looks like
Several measures are low-cost and do not need new regulators:
- Mandatory CAA with account binding for high-value domains. Operators of large brands should publish them across every ccTLD variant they own, including ones they hold defensively.
- CT monitoring as a baseline duty. Free tools already exist, and the Google guidance makes clear that browser-side blocking should not be the only defense.
- Registry security support rather than registry sanctions. ICANN, regional bodies and the technical community can fund and share hardening practices such as registry lock, hardware-backed credentials and incident-sharing channels. Smaller operators lack resources, not intent.
- CA-side friction for sensitive names. CAs could add extra checks, such as delaying issuance or alerting the owner when DNS changes sharply right before a request for a famous brand. The CA/Browser Forum is the right venue for this.
- Transparent post-incident reporting. Registries and CAs should publish what happened. The lessons from this incident depend on disclosure.
The bottom line
The lesson of the hijacks is not that registries need to be supervised from above. It is that the web's trust anchors are more distributed than the security model assumes. The defenses that contained the damage were Certificate Transparency and fast browser action. Policy should extend them to more domain owners and more CAs, and fund hardening for the operators on whom everyone depends. Heavier mandates could slow that work and give governments more control over the namespace.