
Ghana’s .gh internet domain registry was among three country-code registries compromised by attackers who obtained unauthorised security certificates for Google domains and other organizations, disclosed about the hack.
The attacks also affected Sierra Leone’s .sl and American Samoa’s .as registries. Google said its own systems were not breached. Instead, attackers manipulated authoritative Domain Name System records held through the affected third-party infrastructure.
The changes enabled the attackers to obtain trusted HTTPS certificates for domains they did not legitimately control. Such certificates could support website impersonation if users’ connections were redirected to attacker-controlled servers. Their issuance alone does not establish that private information was intercepted.
Google blocked the identified certificates in Chrome through its emergency certificate-blocking mechanism, known as CRLSets, and worked with the issuing certificate authorities to have them revoked. The company said Chrome users did not need to take action to receive those protections.
Further checks of public Certificate Transparency records pointed to other potentially affected organizations. Google extended its Chrome blocking measures to those certificates and contacted affected organizations where possible.
The company urged domain owners to examine certificate records and strengthen issuance restrictions, while cautioning that its investigation might not have identified every affected domain.
Source: Omanghana


