Global internet infrastructure security

Three Hijacked Country Registries Show Domain Validation Is Only as Strong as the Weakest TLD Operator

Attackers who compromised the .gh, .sl and .as registries obtained trusted TLS certificates for Google domains. The fix is better monitoring, not more state control.

ccTLD Hijacks and TLS Validation Defenses People of Internet Research · Global 3 Registries compromised .gh, .sl and .as were hijacked. Mar 2025 MPIC mandatory since CAs must corroborate validation fr… Mar 2026 DNSSEC validation mandatory Required at the primary network pe… peopleofinternet.com
ccTLD Hijacks and TLS Validation Defen… People of Internet Research · Global 3 Registries compromised Mar 2025 MPIC mandatory since Mar 2026 DNSSEC validation mandatory peopleofinternet.com

Key Takeaways

On October 6, 2026, Google's Chrome team disclosed that attackers had compromised the country-code registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as). They changed authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains and other organizations' domains. Google says its own systems were not breached, and it has no reason to believe the issuing certificate authorities did anything wrong. Chrome blocked the Google certificates through CRLSets, used Certificate Transparency logs to find other affected organizations and block their certificates, and worked with the CAs on revocation so other browsers were covered too (Google).

The attack worked because the system behaved as designed

A public CA issuing a certificate through domain validation is checking one thing: whether the applicant controls the domain's DNS at that moment. An attacker who controls the registry controls that answer. As Startup Fortune put it, the CA "has no way to know the difference" between legitimate and fraudulent DNS control, so every domain under a compromised extension is only as trustworthy as the attacker allows (Startup Fortune). That piece also notes the weakness is not new. A Let's Encrypt certificate was once issued for google.tg after Togo's registry was compromised.

The incident therefore does not show careless CAs. It shows that the web's trust model has a structural dependency: roughly 250 country registries, run with very different security budgets, sit upstream of every certificate issued under their names.

The case for stricter control

The strongest argument for tighter regulation is that the risk is systemic and the party that bears it is not the party that controls it. A small registry in a small economy can be the entry point to attacks on global brands. Mandatory security standards, audits or even licensing of registry operators would, on this view, be proportionate to a risk that crosses borders. The argument deserves a serious answer.

Why mandates are the wrong tool

The answer is that the layers that actually worked in this incident were voluntary, technical and fast. Chrome acted within days of learning of the hijacks, and Certificate Transparency logs let the team find victims it had never been told about. Google's recommendations to domain owners are practical. Monitor CT logs, which "provides a near real-time alert whenever a certificate is issued", and publish CAA records with account bindings to restrict which CAs can issue (Google).

A licensing regime would be slow, would be applied unevenly across jurisdictions, and would invite governments to treat registry oversight as a lever over domain content. Anyone who values an open, single, interoperable internet should be wary of that. The ccTLD model works because operators answer to local communities, and a global compliance layer would weaken it. It would also not stop a determined intruder.

The existing hardening is real but incomplete

The CA/Browser Forum has already tightened validation. Its Baseline Requirements made Multi-Perspective Issuance Corroboration mandatory from March 15, 2025. CAs must corroborate domain validation and CAA results from multiple network perspectives. DNSSEC validation became mandatory for the primary network perspective from March 15, 2026 (CA/Browser Forum).

Those controls defend well against attacks on the network path, such as BGP hijacks that mislead a single validation vantage point. They are weaker against this incident. If an attacker controls the registry's authoritative data, every perspective sees the same altered answer. DNSSEC authenticates that data came from the zone and was not modified in transit (ICANN), but a compromised registry can potentially change delegation and signing data at the source. This is analysis, not something the disclosures have confirmed. Google's post, for its part, does not discuss DNSSEC or multi-perspective validation. We do not yet know how the registries were breached or how long the attackers had access, and any policy conclusion should wait for that.

What proportionate response looks like

Several measures are low-cost and do not need new regulators:

The bottom line

The lesson of the hijacks is not that registries need to be supervised from above. It is that the web's trust anchors are more distributed than the security model assumes. The defenses that contained the damage were Certificate Transparency and fast browser action. Policy should extend them to more domain owners and more CAs, and fund hardening for the operators on whom everyone depends. Heavier mandates could slow that work and give governments more control over the namespace.

Sources & Citations

  1. Google: Chrome's Response to Recent ccTLD Registry Hijacks
  2. CA/Browser Forum Baseline Requirements
  3. Help Net Security: ICANN calls for wholesale DNSSEC deployment
  4. Startup Fortune: Hackers Used Hijacked Country Domains