Hackers obtain counterfeit TLS certificates for Google and other large services
By Dan Goodin · Oct 6, 2026, 2:21 PM CDT
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, th
Excerpt shown under fair-use limits. Full text remains with the original publisher.
People in this coverage
Explore their history and attributable record. Being mentioned does not imply endorsement.
Layer 1 · Claims & fact checks
AI analysisLayer 3 · Reporting analysis
AI analysisSensational languageThe headline uses the term “Hackers” and “counterfeit” to evoke alarm, framing the incident as a high‑profile breach.
Technical jargonThe article includes technical details about domain control validation and TLS certificates, which may be unfamiliar to lay readers and serves to convey authority.
Authority appealRepeated references to Google’s statements position the company as the primary source of information, lending credibility but limiting perspective to a single stakeholder.
Context
AI analysisMissing context
The article does not explain how the attackers initially gained access to the ccTLD registries, the timeline of the intrusion, the specific brands or services affected beyond Google, the scale of the certificate misuse, or any independent verification beyond Google's statement.
Important context
Understanding the role of domain control validation in TLS certificate issuance clarifies why control of DNS records enables counterfeit certificates. The response by Google—blocking certificates in Chrome and revoking them with authorities—highlights mitigation steps but does not address broader systemic vulnerabilities in the certificate issuance process.
Opinion vs. reporting
AI analysisThe piece primarily presents factual reporting of the incident and Google's response, with minimal editorializing. Technical explanations of TLS certificates are provided for context but do not constitute opinion.