Attackers compromised the domain registries for three country-code top-level domains (.gh, .sl, and .as) and obtained unauthorized HTTPS certificates for Google domains, Google disclosed on October 6.

The attacks targeted the registries themselves rather than Google's infrastructure. By gaining control of the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) registries, attackers obtained fraudulent certificates that would allow them to impersonate legitimate websites over encrypted connections.

The compromise put all domains under those three ccTLDs at risk. The attackers leveraged their registry access to request and receive HTTPS certificates for Google domains, which represents a significant threat to user security. With valid certificates, attackers could intercept traffic and conduct man-in-the-middle attacks while appearing legitimate to browsers and users.

Google's own systems were not directly breached in this incident. The vulnerability lay in the compromised domain registry infrastructure that manages the .gh, .sl, and .as extensions. This represents a critical weak point in the domain name system, where registry operators control the ability to issue domain registrations and manage certificate issuance.

The incident highlights how threats to domain registries extend beyond the registries themselves. When registries are compromised, the impact cascades to all domain holders under those extensions. Users accessing any .gh, .sl, or .as domain during the compromise window faced potential interception or spoofing attacks.

The discovery underscores ongoing challenges in securing the foundational infrastructure of the internet. Domain registries occupy critical positions in the trust chain for HTTPS certificates and domain management. A compromise at this level can affect thousands or millions of domain holders without their direct involvement or awareness.