Skip to content
Back to Insights
moderate severityinsightUnconfirmed · 18
Intelligence assessmentWest AfricaSierra Leone · Sierra LeoneRelevance: CountryAutomated ingestion — not analyst reviewed

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Sierra Leone · Sierra LeoneEvent: 07 Oct 2026, 18:48 UTCLast updated: 07 Oct 2026, 21:49 UTC
Free to read · no sign-up
Read the full reportContinue to the full article at The Hacker News — free, no sign-up.Open full article
Reported detail
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted
hackernews-cyber
Verification confidence
Unconfirmed
18/100
Multi-source verification score
1 source · 0 layers

Single-thread or unattributed reporting. Treat as an early warning only, pending corroboration.

Six-layer coverage
  • L1 Conflict & armed groups
    No matched signal (ACLED, UCDP, GDELT)
  • L2 Early warning & emergencies
    No matched signal (GDACS, ReliefWeb, FEWS NET, UN OCHA, WHO)
  • L3 GEOINT & situational awareness
    No matched signal (Copernicus, NASA FIRMS, USGS)
  • L4 Cybersecurity
    No matched signal (AlienVault OTX, AbuseIPDB, URLhaus)
  • L5 Strategic & political risk
    No matched signal (GDELT, OpenSanctions, ISS)
  • L6 Verification
    No matched signal (Analyst desk checks, OSINT verification)
How this score was reached
  • Independent reporting sources+8 / 30

    Single-source reporting (The Hacker News). No independent publisher has been matched to this event yet.

  • Cross-layer corroboration0 / 25

    The reporting could not be attributed to any of the six collection layers.

  • Structured / instrument evidence0 / 15

    No conflict-event dataset (L1) or geospatial/GEOINT record (L3) has been matched — reporting is narrative only.

  • Traceable citation+10 / 10

    A direct link to the primary reporting is published with the record.

  • Location resolved0 / 8

    The event is not resolved to coordinates; only a place name is held.

  • Analyst verification (L6)0 / 12

    Awaiting analyst desk verification; the record stands as collected.

Score is computed from collection metadata (independent publishers, collection layers, citation, geolocation, analyst review). It measures how well the event is corroborated, not how severe it is.

Credibility
Confidence
Low
Source reliability
Not graded

Inclusion in this library is not an endorsement of a source. Ungraded items have not yet been assessed by an analyst.

Source provenance
Source
The Hacker News
Source type
Open source
Published
Not provided by source
Event date
07 Oct 2026 18:48 UTC
Data as of
07 Oct 2026 18:48 UTC
Last verified
07 Oct 2026 21:49 UTC
Drafting
Analyst desk
Open original source
Primary reporting
CitationThe Hacker News· Event date 07 Oct 2026, 18:48 UTC· Recorded 07 Oct 2026, 21:49 UTC
thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html(opens the original report in a new tab)
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leo…
Excerpt captured at fetch

Source names are cited under fair use for editorial commentary. Mazin Intel is not affiliated with these organisations and reproduces no proprietary content.

Sign in to save
More from Insights

For shipowners, insurers and risk teams

Need a decision-ready briefing on this risk?

Country, port and voyage briefings with named sources, stated confidence and clear evidence limits.