Hijacked registries minted real Google certificates. Property fraud already has the fix.
Attackers took over the .gh, .sl and .as registries and got valid certificates for Google's names. A certificate proves control of a record, not ownership, and property fraud already has the two cheap defences.
On Tuesday, 6 October, Google's Chrome security team said attackers had hijacked three country-code domains: .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. They did it by compromising the registry operations behind those endings, then changed the DNS records for names like google.com.gh and youtube.sl and asked certificate authorities for HTTPS certificates. They got them. Google says "These incidents did not involve a compromise of Google's systems."
The Hacker News went through the public certificate logs the next day and found 12 certificates across seven Google and YouTube names, 11 from Let's Encrypt and one from ZeroSSL, logged between 22 and 27 September. All of them have since been revoked.
The question I want to work out: if Google, of all companies, can have valid certificates issued for its own names without anyone touching its systems, what is a smaller company supposed to do about the domains it owns?
What actually happened
A certificate authority doesn't check who owns a domain. It checks who controls it, usually by asking the applicant to put a value in the domain's DNS or on a web server under that name. Whoever controls the records passes. Once the attackers controlled the registry for .gh, they controlled the records for every name under it, so google.com.gh passed.
The Hacker News notes that Google sees no reason to think the certificate authorities did anything wrong. They followed the rules. The rules check the record, and the record had been taken.
Chrome blocked the certificates with its own revocation lists and worked with the authorities to revoke them. It also found certificates for "several leading global brands and widely used online services" in the logs and blocked those. But the post is blunt about the limit: browser-side protection "should not be relied on to protect your users," because it doesn't cover people on other browsers.
My first reaction, and why it was wrong
My first reaction was that a CAA record would have stopped this. CAA is the DNS record where you say which certificate authorities are allowed to issue for your name. Google's names had one.
But Google's own post explains why that doesn't help in the moment: "While CAA can not prevent certificate issuance during an active DNS hijack". Of course it can't. The CAA record lives in the same DNS the attacker now controls. They can change it along with everything else. What CAA does do, with an account binding, is stop a validation made during the hijack from being reused later, after the owner has the records back.
So the honest answer is that nothing on the owner's side prevents issuance while the registry is compromised. What the owner can do is find out fast and limit the damage after.
The same problem, with houses
This is where property fraud helped me think. In England and Wales, HM Land Registry holds the register of who owns land. A fraudster who can impersonate the owner well enough to get the register changed can sell or mortgage a house they don't own. The register is the record, and the record is what buyers and lenders check.
Land Registry offers owners two things, and they line up almost exactly with Google's two recommendations.
The first is Property Alert. It's free, covers up to 10 properties, and emails you when someone applies to change the register for your property. The gov.uk page is clear that it "will not automatically block any changes to the register". It tells you, so you can act. That's what Certificate Transparency monitoring is: every public certificate gets logged, and if you watch the logs for your names, you find out when one is issued that you didn't ask for.
The second is a restriction. It stops a sale or mortgage being registered "unless a conveyancer or solicitor certifies the application was made by you." You name in advance who has to vouch for any change. That's the idea behind a CAA record bound to your own account: only this authority, only for this account.
And the place the analogy is most useful is the list of who's at risk. Land Registry says "You're more at risk if" the property is rented out, you live overseas, "the property's empty", or it isn't mortgaged. In other words, the houses nobody is watching.

Which domains are the empty houses
That's the part I'd take back to any company. The names that got hit were country versions of Google's domains: google.com.gh, google.as. For Google some of those are live local sites. For most companies, the country versions of their name are registered so nobody else can have them, then parked. Google's advice is that monitoring should cover the "entire domain portfolio, including parked or regional ccTLD properties." Those are the empty houses. Nobody lives there, nobody checks the post, and the only thing tying them to you is a record held by a registry you didn't pick and can't audit.
The fault line in the analogy is worth naming. A house restriction lives in the Land Registry's own system, out of the fraudster's reach. A CAA record lives in the DNS the attacker has just taken. So the domain version of a restriction is weaker in the moment and only really bites afterwards. The alert, though, works the same in both: it doesn't depend on the compromised system, because the certificate logs are public and separate.
I've written about how fast attackers move once details are public. This is the quieter version of the same lesson. The attack doesn't have to touch you. It only has to touch the record that says you're you.
What I'm confident of, and what I'm not
The hijacks, the 12 certificates, the dates, Chrome's response and the advice on CT monitoring and CAA are established from Google's post and The Hacker News. Property Alert, restrictions and the risk list are established from gov.uk. The mapping between them is my inference, and it breaks where I said: a CAA record can be rewritten by the attacker, a restriction can't. That most companies don't watch their parked country domains is a guess. I haven't seen data either way.
The claim, in one sentence: a certificate proves you control a name's record, not that you own it, so the names most at risk are the ones you own and never watch, and the cheap protection is the same as for an empty house: an alert on the record and a named person who must sign off on any change.
Sources
Chrome Secure Web and Networking Team, "Chrome's response to recent ccTLD registry hijacks", Google, 6 October 2026. https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
"Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains", The Hacker News, 7 October 2026. https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html
HM Land Registry, "Protect your land and property from fraud", GOV.UK. https://www.gov.uk/protect-land-property-from-fraud