Google responded to ccTLD registry hijacks in .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa).
Attack chain: attackers compromised third-party ccTLD registries (not Google systems), modified authoritative DNS records, obtained unauthorized HTTPS certificates for Google domains and other organizations via domain validation.
Google blocked unauthorized certificates in Chrome via CRLSets and coordinated CA revocation. Google states CAs did not act improperly given the attack nature.
Recommendations: monitor Certificate Transparency logs; use restrictive CAA records (cannot prevent issuance during active DNS hijack but helps post-incident); review CT entries for .gh/.sl/.as domains.
Google cannot guarantee all counterfeit certificates identified; Chrome interventions may not protect non-Chrome users.