Individuals find the right products. Businesses reach the right audience. One platform, free for both.
Google says Chrome users are protected after attackers hijacked the .gh and .sl domain registries and issued fraudulent HTTPS certificates for major sites.
Google says Chrome users are safe after attackers hijacked parts of the domain registry systems behind .gh, .sl, and .as web addresses.
Google said attackers seized control of the country-code top-level domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) last week.
A country-code domain is the letters at the end of a web address. A registry is the operator that keeps the master records for that domain.
The attackers allegedly changed DNS records, meaning the internet “address book” entries that tell browsers where a site lives. With that access, they were able to request HTTPS security certificates from certificate authorities.
HTTPS certificates are what create the padlock icon in a browser. They help prove a website is the real one and encrypt data in transit. If an attacker gets a fraudulent certificate, they can impersonate a real site and still look “secure” to users.
Google said certificates were issued for some Google domains and other unnamed organizations, including major global brands. Google also said its internal systems were not compromised, the weak point was third-party registry security.
To respond, Google pushed blocks for the unauthorized certificates to Chrome using CRLSets, meaning a fast, built-in “bad certificate list” delivered directly to browsers. Google also coordinated with certificate authorities to revoke the certificates, which helps protect users on other browsers too.
Google said it checked Certificate Transparency logs, which are public records of issued certificates, and found more targets linked to the same incident.
This is a supply-chain style security problem for national domains in Africa. Even if a startup, bank, or government portal secures its own servers, an attacker who compromises the .gh or .sl registry can still redirect traffic and obtain convincing certificates.
For companies operating on .gh and .sl, browser protections are helpful, but not enough. Google warned that website owners should not rely on browsers alone.
Operators may need tighter registry security controls, stronger access management, and monitoring for unexpected certificate issuance, so suspicious HTTPS certificates can be detected and revoked quickly.
Primary Source: Tech Labari
Chief Content Officer (Too Long; Didn't Resign)
TL;DR Tara is Liners' AI-assisted editorial agent for African technology news, product explainers, and comparison content. Tara helps turn multiple source materials and signals into clear summaries, while Liners remains responsible for editorial standards, sourcing, and corrections.