A series of attacks against the domain registries for Ghana, Sierra Leone and American Samoa has demonstrated that the security of HTTPS depends on far more than the organization named in a web address.
DNS control enabled valid certificate requests
The attackers compromised infrastructure associated with the .gh, .sl and .as country-code top-level domains. By changing authoritative DNS records, they could demonstrate apparent control of targeted domains and request legitimate TLS certificates from public certificate authorities.
Certificate Transparency records reviewed by The Hacker News showed at least 12 unauthorized certificates covering seven Google and YouTube domains. Eleven were issued by Let's Encrypt and one by ZeroSSL between September 22 and September 27. The certificates were later revoked.
Google said its own systems were not compromised. The company blocked the certificates in Chrome using CRLSets, an emergency mechanism for rejecting selected certificates, and worked with certificate authorities to extend protection beyond its browser. Google also found indications that other global brands and widely used online services may have been affected.
Why the padlock is not enough
Users are commonly taught that an HTTPS padlock means a website is trustworthy. In reality, it confirms that the browser has established an encrypted connection with a system presenting a recognized certificate. If attackers control DNS long enough to obtain that certificate, the encrypted connection may terminate at malicious infrastructure.
The incident therefore represents a supply chain problem in internet identity. A company can secure its applications, accounts and internal networks yet still face impersonation if a registry, registrar, DNS provider or certificate validation process is manipulated.
Defensive priorities for domain owners
- Monitor Certificate Transparency logs for every registered and parked domain.
- Use registry locks and strong administrative authentication where available.
- Limit certificate issuance through restrictive CAA records.
- Alert on unauthorized nameserver and DNS record changes.
- Maintain an emergency process for certificate revocation and DNS restoration.
CAA records can reduce exposure, particularly after legitimate DNS control has been restored, but they cannot fully stop an attacker who can actively modify authoritative records. I believe organizations should treat domain and certificate monitoring as part of their security operations program rather than a task left solely to web administrators. Brand protection, DNS security and certificate management now belong in the same risk conversation as identity and endpoint defense.
