---
title: "Google Chrome Blocks Fake .gh and .sl HTTPS Certificates"
description: "Google says Chrome users are protected after attackers hijacked the .gh and .sl domain registries and issued fraudulent HTTPS certificates for major sites."
canonical_url: "https://liners.com/news/google-chrome-blocks-fake-gh-sl-https-certificates"
markdown_url: "https://liners.com/news/google-chrome-blocks-fake-gh-sl-https-certificates.md"
type: "article"
language: "en"
published_at: "2026-10-07T14:00:52.949Z"
updated_at: "2026-10-07T14:00:52.997Z"
---

# Google Chrome Blocks Fake .gh and .sl HTTPS Certificates

Google says Chrome users are protected after attackers hijacked the .gh and .sl domain registries and issued fraudulent HTTPS certificates for major sites.

## Breadcrumbs

- [News](/news)
- [Google Chrome Blocks Fake .gh and .sl HTTPS Certificates](/news/google-chrome-blocks-fake-gh-sl-https-certificates)

## Content

## In Short
Google says Chrome users are safe after attackers hijacked parts of the domain registry systems behind .gh, .sl, and .as web addresses.

## What Happened
Google said attackers seized control of the country-code top-level domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) last week.

A country-code domain is the letters at the end of a web address. A registry is the operator that keeps the master records for that domain.

The attackers allegedly changed DNS records, meaning the internet “address book” entries that tell browsers where a site lives. With that access, they were able to request HTTPS security certificates from certificate authorities.

HTTPS certificates are what create the padlock icon in a browser. They help prove a website is the real one and encrypt data in transit. If an attacker gets a fraudulent certificate, they can impersonate a real site and still look “secure” to users.

Google said certificates were issued for some Google domains and other unnamed organizations, including major global brands. Google also said its internal systems were not compromised, the weak point was third-party registry security.

To respond, Google pushed blocks for the unauthorized certificates to Chrome using CRLSets, meaning a fast, built-in “bad certificate list” delivered directly to browsers. Google also coordinated with certificate authorities to revoke the certificates, which helps protect users on other browsers too.

Google said it checked Certificate Transparency logs, which are public records of issued certificates, and found more targets linked to the same incident.

## Why It Matters
This is a supply-chain style security problem for national domains in Africa. Even if a startup, bank, or government portal secures its own servers, an attacker who compromises the .gh or .sl registry can still redirect traffic and obtain convincing certificates.

For companies operating on .gh and .sl, browser protections are helpful, but not enough. Google warned that website owners should not rely on browsers alone.

Operators may need tighter registry security controls, stronger access management, and monitoring for unexpected certificate issuance, so suspicious HTTPS certificates can be detected and revoked quickly.

## Sources and products

- [Tech Labari](https://techlabari.com/hackers-hijacked-ghana-and-sierra-leone-web-domains-google-says-chrome-users-are-safe)

## Related pages

- [Infrastructure](/news)

## Access and citation

- [Canonical HTML page](https://liners.com/news/google-chrome-blocks-fake-gh-sl-https-certificates)
- [Markdown route index](/sitemap.md)
- [Agent access guide](/llms.txt)
