Hackers hijacked website domain in Ghana, Sierra Leone, American Samoa- Google discloses

0

Attackers seized control of the internet address systems for Ghana, Sierra Leone and American Samoa last week, putting websites using the .gh, .sl and .as country-code domains at risk.

Google disclosed the incident in a blog post, saying the attackers compromised third-party registries responsible for managing the three country-code top-level domains.

The breach allowed the attackers to alter Domain Name System (DNS) records, which direct internet users to the servers hosting websites. By changing those records, the attackers could redirect traffic and falsely demonstrate control over targeted domains.

Google said the attackers subsequently obtained security certificates for several of its websites, as well as domains belonging to other organisations, including major global brands and widely used online services.

The certificates are normally used to establish HTTPS connections and display the padlock symbol in web browsers. They are designed to assure users that they are communicating with the legitimate website and that their connection is encrypted.

However, Google said fraudulent certificates could allow attackers to impersonate legitimate websites while maintaining the appearance of a secure connection.

Google stressed that its own systems were not compromised. Instead, the weakness was found within the third-party registries responsible for operating the affected country-code domains.

The company said certificate authorities that issued the certificates were likely deceived by the manipulated DNS records and therefore did not necessarily act improperly.

Following the discovery, Google moved to block the unauthorised certificates for its properties through Chrome’s CRLSets, which allow Chrome to receive information about revoked or untrusted certificates.

Google also worked with the relevant certificate authorities to revoke the certificates, helping protect users of other browsers.

The company subsequently examined Certificate Transparency logs, public records that track trusted security certificates issued across the internet. The review revealed that other organisations had also been targeted during the attacks.

Chrome blocked the additional certificates, while Google said it contacted affected organisations where possible, although it did not identify them.

Google said Chrome users do not need to take any action because the browser’s protections have already been updated.

The incident has also raised concerns about the security of country-code domain registries, which often operate with smaller teams and fewer resources than major technology companies despite being critical to national internet infrastructure.

A compromise of a country-code registry can potentially affect a large number of websites operating under that domain, including government portals, banks, telecommunications companies, media organisations and startups.

For Ghana, the incident is particularly significant because the .gh domain is used by a wide range of public institutions, businesses and digital services.

Google did not identify the specific security weakness exploited in the three registries, nor did it disclose how the attackers gained access or how long they maintained control.

The company said it would continue working with the wider internet security industry to reduce the impact of DNS and routing attacks.

Among the measures being considered are shorter certificate validity periods and tighter limits on how long certificate authorities can rely on previous domain-control checks.

Google said these measures would reduce the period during which a stolen or fraudulently obtained certificate could be exploited.

The company linked the efforts to the Chrome Root Program, which determines the certificate authorities trusted by Chrome, as well as its emerging Chrome Quantum-Resistant Root Program.

The incident highlights a broader challenge for internet security: even organisations with strong cybersecurity systems can remain vulnerable when the infrastructure managing their domain names is compromised.

LEAVE A REPLY

Please enter your comment!
Please enter your name here