Attackers seized control of the internet address systems for Ghana, Sierra Leone and American Samoa last week, in a blog post by Google.
The breach put every website ending in .gh, .sl or .as at risk.
The attackers used that access to obtain security certificates for several Google websites. They also obtained certificates for domains belonging to other organizations, including some leading global brands and widely used online services.
Google said its own systems were not compromised. The weak point was the third-party registries that manage the three country-code domains.
What Happened
Every country has its own top-level domain, the letters at the end of a web address. Ghana’s is .gh. Sierra Leone’s is .sl. American Samoa’s is .as.
Each domain is run by a registry. The registry keeps the master records that tell computers where a website lives. These are known as DNS records.
The attackers broke into those registries and changed the records. That let them redirect traffic and prove, falsely, that they controlled certain domains.
With that false proof, they asked certificate authorities for HTTPS certificates. These certificates are what make the padlock appear in a browser. They tell users a site is genuine and their connection is private.
A fraudulent certificate lets an attacker impersonate a real website. Users could see a secure connection while their data went to criminals.
Google said the certificate authorities that issued the certificates likely did nothing wrong. They were deceived by the altered records.
How Google Responded
Google said it acted immediately once it learned of the attacks.
Chrome blocked the unauthorized certificates for Google properties using CRLSets. This is a mechanism that pushes lists of bad certificates directly to Chrome browsers.
Google also worked with the certificate authorities to revoke the certificates. That step protects people using other browsers.
The company then checked Certificate Transparency logs. These are public records of every trusted certificate issued. The logs showed that other organizations had also been targeted in the same attacks.
Chrome blocked those certificates too. Google said it contacted affected organizations where possible. It did not name them.
Chrome users do not need to do anything to be protected, the company said.
Why It Matters for Africa
The incident exposes a structural weakness. Country-code registries are often run by small operators with limited security budgets. Yet they sit beneath government portals, banks, telecom companies and news outlets.
When one registry falls, every site under it becomes vulnerable. A business can have strong security and still be exposed through its national domain.
Ghana’s .gh domain hosts government services, financial institutions and a growing number of startups. Sierra Leone’s .sl serves a similar role at a smaller scale.
Neither registry has been named by Google as responsible for a specific failure. The blog post did not say how the attackers gained access or how long they held control.
What Comes Next
Google said it will keep working with the wider industry to reduce the damage from DNS and routing attacks.
That includes shortening how long certificates remain valid. It also includes limiting how long certificate authorities can reuse past domain checks. Both changes shrink the window in which a stolen certificate is useful.
The company tied that work to the Chrome Root Program, which decides which certificate authorities Chrome trusts. It also cited its new Chrome Quantum-resistant Root Program.
For now, the burden falls largely on domain owners. Google’s message was blunt: browsers can help, but they cannot be the last line of defense.