Last October, Google disclosed that attackers had compromised the registries for three country-code top-level domains—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and obtained fraudulent HTTPS certificates for Google-owned domains. The attack exploited a critical weakness in domain infrastructure: the trust chain between registry operators and Certificate Authorities. Understanding this vulnerability matters for anyone running infrastructure, especially those operating or relying on ccTLD services.

How Registry Compromise Enables Certificate Forgery

Domain registries maintain authoritative DNS records for all domains under their TLD. A registry operator typically has the technical ability to modify zone files, DNS records, and nameserver assignments. If an attacker gains control of a registry's systems—through credential theft, unpatched vulnerabilities, or social engineering—they can redirect nameserver queries or inject false DNS responses.

Certificate Authorities rely on DNS validation to prove domain ownership during issuance. The most common method is DNS-01 validation: the CA queries a specific DNS record to confirm the applicant controls the domain. If an attacker controls the registry, they can forge that DNS response, convincing the CA that the attacker owns any domain under that TLD.

This is precisely what occurred with .gh, .sl, and .as. The attacker inserted themselves into the DNS chain, answered validation queries on behalf of Google domains, and obtained valid certificates that browsers would trust. No breach of Google's own systems was necessary. The attack worked because the registry—positioned at a higher trust layer—was compromised first.

The Fragility of Small and Emerging ccTLDs

Smaller country-code registries often operate with fewer resources than the infrastructure they manage requires. Security budgeting is frequently an afterthought. A typical registry may consist of a handful of staff managing DNS infrastructure, domain databases, and customer systems. Sophisticated attackers targeting these registries have leverage: the barrier to entry is lower than attacking major TLDs like .com or .uk.

The specific registries targeted—Ghana, Sierra Leone, and American Samoa—are all relatively small by internet governance standards. Their lower profile and smaller operational budgets make them likelier targets for attackers seeking to abuse the trust that CAs place in DNS responses from authoritative nameservers.

For domain owners under these TLDs, this creates a systemic risk independent of their own security posture. An infrastructure operator could implement perfect DNS security practices, use strong passwords, and enable multi-factor authentication, yet still have their domain hijacked if the registry itself is compromised.

Implications for Domain and Certificate Security

This incident underscores why Certificate Transparency (CT) logs matter. When a certificate is issued, it is logged in multiple public CT logs that anyone can query. Google and other organisations monitor these logs for unexpected certificates issued for their domains. CT logs caught the fraudulent certificates in this attack, allowing remediation before widespread abuse.

For organisations operating domains under smaller or emerging ccTLDs, several measures reduce risk. First, monitor CT logs for your domains regularly. Tools like Censys, Splunk (which indexes CT logs), or domain-specific monitoring services can alert you to certificates issued for your domains without your knowledge.

Second, consider using DNSSEC (Domain Name System Security Extensions) if your registry supports it. DNSSEC cryptographically signs DNS responses, making it difficult for an attacker to forge them even if they've compromised a registry. Many registries, particularly smaller ones, have not implemented DNSSEC, though adoption is slowly increasing.

Third, if your business is sensitive to domain security (e-commerce, financial services, security infrastructure), diversify your presence across TLDs. Relying solely on a high-risk ccTLD concentrates risk. A geographically appropriate .com or other major TLD registration as a backup provides redundancy if the primary TLD is compromised.

A Broader Fragmentation Problem

The internet's distributed governance model means security is only as strong as the weakest registry operator. As more ccTLDs come online and existing ones modernise (or fail to modernise) their infrastructure, this tension between accessibility and security will persist.

Registry operators must treat their systems as critical infrastructure. The ability to issue valid HTTPS certificates for any domain under a TLD gives an attacker the keys to widespread fraud, phishing, and credential theft. Until smaller registries receive adequate investment in security tooling, staff training, and infrastructure hardening, the risk remains real.