← Back to news
The Register - Security7 Oct 2026 · 1 min read

Attackers reportedly hijacked top-level domains to obtain fraudulent certificates

Security researchers reported that attackers compromised control of several top-level domains and used that access to obtain unauthorized TLS certificates for prominent organizations, including Google...

Security researchers reported that attackers compromised control of several top-level domains and used that access to obtain unauthorized TLS certificates for prominent organizations, including Google. The incident highlights how weaknesses in domain validation processes can affect the broader web certificate ecosystem.

According to the report, the attackers were able to alter DNS records associated with the affected top-level domains. That control allowed them to satisfy domain-control checks used by certificate authorities and request certificates for domains they did not legitimately own.

Potential impact

A fraudulent certificate could be used to impersonate a legitimate website in certain attack scenarios, particularly where an attacker can also redirect victim traffic or position themselves between a user and the intended service. Modern browser protections, certificate transparency monitoring, and certificate revocation mechanisms can limit exposure, but unauthorized issuance remains a serious concern.

The affected certificates were reportedly identified and revoked after the activity was discovered. Organizations whose names appeared on the certificates were not necessarily breached; rather, their domain identities may have been targeted through the compromised validation infrastructure.

Lessons for defenders

  • Monitor certificate transparency logs for newly issued certificates involving corporate domains.
  • Use DNS security controls, including DNSSEC where appropriate, and protect registrar and DNS provider accounts with strong authentication.
  • Restrict certificate issuance through CAA DNS records to approved certificate authorities.
  • Maintain incident-response procedures for suspected certificate misissuance, including rapid revocation requests and public communications.

The case underscores that trust in HTTPS depends not only on website operators, but also on registries, DNS providers, certificate authorities, and the systems used to validate domain ownership.

Share this article:TwitterLinkedIn