Google disclosed that attackers hijacked the .gh, .sl, and .as country-code registries and changed authoritative DNS records to pass domain-validation checks, obtaining at least twelve TLS certificates for seven Google-owned names including google.com.gh, google.sl, and google.as. Let's Encrypt issued eleven and ZeroSSL one, all logged between September 22 and 27 and since revoked, and Chrome also blocked them through CRLSets. Such certificates let an attacker impersonate the real sites, though Google has not confirmed any misuse and says its own systems were not breached. Google advises domain owners to monitor certificate transparency logs and publish strict CAA records tied to their certificate authority.