$ 44.85 € 50.38 zł 11.51
+17° Kyiv +14° Warsaw +9° Washington

Attackers obtained counterfeit TLS certificates for Google domains — Ars Technica

Fedir Kryshtovskyi 07 October 2026 01:28
Attackers obtained counterfeit TLS certificates for Google domains — Ars Technica

Attackers took control of three national domain zones and used it to obtain unauthorized TLS certificates for several Google domains, as well as other major brands and popular online services. Ars Technica reports, citing a Google statement.

Control over DNS records

The attacks targeted the .gh, .sl and .as country-code top-level domains. After taking control of these zones, the attackers changed authoritative DNS records for selected domains. This allowed them to pass the automated domain-control validation that certificate authorities use when issuing certificates.

Google updated Chrome to block all identified unauthorized certificates. The company also worked with certificate authorities to revoke certificates issued for Google resources. Google did not name other affected organizations, and the number of unauthorized certificates issued remains unknown.

More current news is available on the UA.News Telegram channel Telegram.

Risk of cryptographic impersonation

TLS certificates are used to authenticate and encrypt connections to websites, mail servers and other internet infrastructure. They link a domain name to a public cryptographic key, while the private key must be kept only by the resource owner. An unauthorized certificate can allow attackers to cryptographically impersonate the relevant infrastructure.

According to Google, the infrastructure of the owners of the affected domains was not compromised, and certificate authorities complied with the established requirements. Control over the domain zones allowed the attackers to change the IP addresses of selected websites. This enabled them to redirect traffic for these sites, alter authoritative DNS records and name server delegations required to pass domain-control validation.

The company warned domain owners not to rely solely on certificate blocking in browsers. Google recommended monitoring certificate transparency logs for unexpected issuance and publishing restrictive Certification Authority Authorization DNS records to prevent the reuse of cached validation data after DNS control is restored.

Read us on
Download our app