Hackers hijack Google domains after breaching ccTLD registries
Attackers breached third-party operators managing country-code top-level domains for Ghana, American Samoa, and Sierra Leone, then altered DNS records and obtained unauthorized HTTPS certificates to hijack several Google domains.
Why this matters: This one cuts at something people rely on without thinking about it. When you see a padlock and a Google address, you trust it. That trust depends on a chain of operators most people have never heard of. If a registrar running a small country's domain system gets compromised, attackers can redirect traffic and forge certificates that look completely legitimate. The weak link was not Google. It was the infrastructure underneath it, which is exactly where most people are not looking.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.