Definition
A ccTLD registry hijack compromises the operator of a country-code top-level domain (.gh, .sl, .as), granting attackers control over authoritative DNS for all domains under that suffix.
Key Points
- 2026-10-06: Attackers hijacked .gh (Ghana), .sl (Sierra Leone), .as (American Samoa) registries; obtained unauthorized TLS certs for Google and other brands via DV validation (2026-10-07-google-cctld-hijack-chrome-response)
- CAs acted correctly — attackers passed domain control checks by controlling DNS
- google blocked certs via Chrome CRLSets; coordinated CA revocation. Cannot guarantee all certs found
- Precedent: Sea Turtle (2017–2019), US federal DNS tampering (2019)