<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye" -->

---
title: Hackers obtain counterfeit TLS certificates for Google...
description: Attackers compromised three country-code top-level domain registries (.gh, .sl, .as) and used control over DNS records to mint fraudulent TLS certificates...
canonical: https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers obtain counterfeit TLS certificates for Google and other large services | daily.dev
og:description: Attackers compromised three country-code top-level domain registries (.gh, .sl, .as) and used control over DNS records to mint fraudulent TLS certificates...
og:url: https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye
og:image: https://api.daily.dev/og/posts/SaI4cbgyE.png
og:image:alt: Hackers obtain counterfeit TLS certificates for Google and other large services
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers obtain counterfeit TLS certificates for Google and other large services

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

Attackers compromised three country-code top-level domain registries (.gh, .sl, .as) and used control over DNS records to mint fraudulent TLS certificates impersonating Google and other major brands and services. Google says it updated Chrome to block the identified counterfeit certificates and coordinated with other certificate authorities and browser vendors to do the same. Google has not disclosed which of its domains were affected or named the other impacted organizations, and warns it cannot guarantee it has found every unauthorized certificate. Domain owners are advised to monitor Certificate Transparency logs for unexpected certificate issuance against their domains.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/10/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services>

## Questions this post answers

### How did attackers get fraudulent TLS certificates issued for Google domains?

Attackers compromised three country-code top-level domain registries — .gh, .sl, and .as — and modified DNS records for selected domains under those registries. By controlling DNS, they could receive and respond to domain validation checks, allowing them to obtain unauthorized TLS certificates for several Google domains and other major brands from certificate authorities.

_Teams relying on domain validation for certificate issuance can follow TLS supply-chain incidents like this on daily.dev._

### What should I do if I suspect someone issued an unauthorized TLS certificate for my domain?

Check Certificate Transparency logs for any certificate issuance you did not authorize, since every publicly trusted TLS certificate must be logged there. Google recommends domain owners actively monitor these logs rather than assume certificate authorities will catch fraudulent issuance, especially after registry-level DNS compromises like the recent .gh, .sl, and .as ccTLD attacks.

_Keep up with evolving PKI and certificate transparency guidance on daily.dev as domain security incidents unfold._

## Similar posts on daily.dev

- [Operation TrustTrap: A Deceptive Domain Spoofing Campaign](https://daily.dev/posts/operation-trusttrap-a-deceptive-domain-spoofing-campaign-cwxqjqs2t) · Cyble · 0 upvotes · 0 comments
- [How to spot a suspicious website](https://daily.dev/posts/how-to-spot-a-suspicious-website-oiu9edxwk) · Securelist · 0 upvotes · 0 comments
- [Google Safe Browsing incident](https://daily.dev/posts/google-safe-browsing-incident-txwfsh2lo) · Hacker News · 2 upvotes · 1 comments

---

Tags: [#google](https://daily.dev/tags/google), [#google-chrome](https://daily.dev/tags/google-chrome)

[View this post on daily.dev](https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers obtain counterfeit TLS certificates for Google and other large services","url":"https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye"},"datePublished":"2026-10-06T20:42:38.423Z","dateModified":"2026-10-06T20:48:13.825Z","description":"Attackers compromised three country-code top-level domain registries (.gh, .sl, .as) and used control over DNS records to mint fraudulent TLS certificates...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6a131b22bc27587108216936494e1e2f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6a131b22bc27587108216936494e1e2f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"google,google-chrome","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Hackers obtain counterfeit TLS certificates for Google and other large services"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-obtain-counterfeit-tls-certificates-for-google-and-other-large-services-sai4cbgye#faq","mainEntity":[{"@type":"Question","name":"How did attackers get fraudulent TLS certificates issued for Google domains?","acceptedAnswer":{"@type":"Answer","text":"Attackers compromised three country-code top-level domain registries — .gh, .sl, and .as — and modified DNS records for selected domains under those registries. By controlling DNS, they could receive and respond to domain validation checks, allowing them to obtain unauthorized TLS certificates for several Google domains and other major brands from certificate authorities. Teams relying on domain validation for certificate issuance can follow TLS supply-chain incidents like this on daily.dev."}},{"@type":"Question","name":"What should I do if I suspect someone issued an unauthorized TLS certificate for my domain?","acceptedAnswer":{"@type":"Answer","text":"Check Certificate Transparency logs for any certificate issuance you did not authorize, since every publicly trusted TLS certificate must be logged there. Google recommends domain owners actively monitor these logs rather than assume certificate authorities will catch fraudulent issuance, especially after registry-level DNS compromises like the recent .gh, .sl, and .as ccTLD attacks. Keep up with evolving PKI and certificate transparency guidance on daily.dev as domain security incidents unfold."}}]}
```

