Hackers Steal Google Domains by Breaching Country-Level Registries

Hackers Steal Google Domains by Breaching Country-Level Registries

In a stunning display of digital incompetence, hackers managed to hijack several Google domains by compromising country-code top-level domain (ccTLD) registries in Ghana, American Samoa, and Sierra Leone. It’s a real shocker that something like this could happen when dealing with the giants of tech. Who could have seen that coming?

These cyber marauders scored unauthorized HTTPS certificates and altered DNS records, which, surprise, surprise, allowed them to redirect legitimate traffic to their own servers. Google is quick to assure everyone that while this breach impacted various domains, their own systems remain untouchable. What a relief for everyone involved.

The hackers exploited a common trick: they accessed DNS records to request HTTPS certificates from Certificate Authorities (CAs) for domains they didn’t own. Apparently, that’s as simple as a couple of clicks if you're the right kind of bad actor. Modifying those records let them assume identities of legitimate brands and serve whatever junk they wanted to visitors—just a casual stroll down the cybercrime lane.

Google’s response? They promptly blocked the unauthorized certificates in Chrome and worked with CAs to revoke them. They notified organizations caught in the crossfire and did a thorough check of Certificate Transparency logs to identify further victims. Isn’t that gracious of them?

However, they gently remind users that their protective measures only cover Chrome. So if you're browsing on any other platform, good luck with that; you might want to invest in some extra precautions.

To play it safe, Google encourages domain owners to monitor CT logs and publish restrictive Certificate Authority Authorization (CAA) records. Sure, that will help—after the fact. Not that they can prevent certificate issuance during an active DNS hijack, but it might save some future headaches once the chaos is over.

Now, if only the tech industry could work just as hard to protect networks proactively as it does to reactively clean up messes. But hey, that would require actual foresight and planning. Instead, we get to witness another episode in the ongoing saga of digital warfare where hackers always seem to be one step ahead.

Read More

Got Something To Say?

Your email address will not be published.