Attackers have been able to issue fraudulent security certificates, which in turn let them redirect visitors from legitimate Google domains to malicious sites. Google’s Chrome Secure Web and Networking Team confirmed the attacks in a security blog post, emphasizing that the incidents did not involve a compromise of Google’s systems. Instead, the hackers were able to compromise third-party operators in order to change the Domain Name Service, the phone book of the internet if you like, records and issue unauthorized HTTPS certificates “covering several Google domains,” Google said , “as well as domains belonging to other organizations.” As far as is known to date, the hijacked domains were found in the country-code top-level domains for American Samoa, Ghana and Sierra Leone.

Google conceded that while it took immediate action to block known fraudulent certificates in Chrome, it “cannot guarantee that our analysis identified every affected domain. The good news is that Google has said that it has worked with the issuing certificate authorities “to ensure the certificates were revoked to protect users in clients other than Chrome.”

It’s reassuring to see Google respond quickly when such attacks are detected, as they can let cybercriminals impersonate legitimate organizations’ websites without triggering security alerts, with potentially disastrous consequences. In this case, the hackers held all the cards: they controlled DNS traffic routing and the private keys for the certificates. As a result, these attacks can go beyond expected phishing and brand impersonation, potentially enabling the interception or alteration of data.

Google says Chrome users don’t need to do anything to stay protected, as all the necessary work has been done behind the scenes. However, domain owners are encouraged to monitor certificate transparency across their entire domain portfolio, including any parked or regional ccTLD properties. The use of Certification Authority Authorization DNS records can also assist by enabling domain owners to declare which certificate authorities are permitted to issue certificates for their domains. “While CAA can not prevent certificate issuance during an active DNS hijack” Google said, “it provides a critical safeguard after DNS control is restored, and can prevent some routing-based and HTTP attacks entirely.”