Google says three national domain registries were hijacked to mint certificates in its name
Two of the three compromised country-code registries are West African. Nobody has been named, and neither Accra nor Freetown has said anything.
Google disclosed on 6 October that attackers compromised three country-code top-level domain registries and obtained unauthorised HTTPS certificates for several Google domains. Google’s own systems were not breached. The exposure runs the other way: any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk, because whoever holds a national registry holds the authority to prove ownership of everything beneath it. No attribution has been published. No statement was found from Ghanaian or Sierra Leonean authorities. The practical reach of this is modest for Google, which can revoke and reissue; it is not modest for anyone whose bank, ministry or newsroom sits under those two suffixes, since the same control that mints a certificate for a Google property mints one for theirs.
Assessment: This reads as an American tech story and is filed as one. It belongs on this desk because the weak point it demonstrates is the under-resourced national registry, and West Africa runs several. For a region where governments have spent the past three years treating connectivity itself as a lever — shutdowns, licence revocations, platform blocks — the quieter risk is that the naming layer beneath all of it is thinly staffed and externally compromisable, with no disclosure obligation and no obvious regulator to report to. Note what is missing: motive, actor, and any official word from the two affected states. Until Accra or Freetown speaks, treat the scope as Google’s account alone.