Hackers compromised the infrastructure behind three country-code top-level domains, using their administrative control to alter DNS records and acquire unauthorized TLS certificates. According to details released by Google, the targeted domain extensions included .gh, .sl, and .as. By manipulating authoritative name servers within those regional namespaces, the intruders successfully intercepted validation requests required to generate new digital credentials.

The breach enabled the threat actors to satisfy automated domain control checks, allowing them to mint valid certificates for several Google domains alongside other prominent online services and global corporate brands. TLS certificates serve as the fundamental trust layer for the modern internet, utilizing cryptographic keys signed by trusted authorities to verify website identities and encrypt web traffic.

By manipulating the underlying DNS responses for the targeted domain names, the attackers were able to masquerade as legitimate domain owners during the automated issuance process. This allowed them to bypass standard authentication safeguards without needing direct access to the victim organizations' internal infrastructure or servers.

In response to the incident, Google deployed security updates in its Chrome web browser to prevent the counterfeit credentials from being recognized as valid. The company also collaborated with the issuing certificate authorities to ensure all identified unauthorized certificates tied to its properties were formally revoked.

What it means

The incident highlights structural vulnerabilities within the public key infrastructure, specifically how automated certificate issuance relies heavily on the integrity of regional domain registries. When top-level domain operators suffer a compromise, the cryptographic assurances that secure web traffic across major platforms can be compromised at the root level.