Unauthorized Google Certificates: Lock Your Store Domain

Affiliate disclosure: This post contains affiliate links. If you buy through them, I may earn a commission at no extra cost to you. Full disclosure

Attackers took over Google and YouTube domains under the .gh, .sl and .as country-code extensions and obtained unauthorized HTTPS certificates, according to a Google security post published Oct. 6.

If you run a store, the lesson is not about Ghana. Whoever controls your DNS can get a browser-trusted padlock for your brand, and a buyer sending $3,000 to a cloned checkout never sees a warning. This is a domain security story for every owner at Ecommerce Paradise, even if your store sits on a plain .com.

Below: what Google and the security press reported, how a DNS change turns into a valid certificate, what it costs a high-ticket store, and six things to do this week. I covered the ASOS breach earlier today. This is the same family of problem, where attackers go after the trust layer around a store instead of the store itself.

Attackers research owners before they strike, and a public LLC filing hands them a home address. Form your LLC with Northwest, the best LLC formation service for ecommerce owners, and keep your own address off the public record. Northwest does not sell your address and lists its own on your public filings. Form your LLC with Northwest →

Attackers Hijacked .gh, .sl and .as to Mint Google Certificates

The Chrome Secure Web and Networking Team at Google published the post on Oct. 6. It says attackers compromised the third-party registries behind three country-code top-level domains: Ghana’s .gh, Sierra Leone’s .sl and American Samoa’s .as. They changed authoritative DNS records and obtained unauthorized HTTPS certificates, per Google’s post.

Google said its own systems were not breached. BleepingComputer reported on Oct. 7 that the hijacks let the attackers pass certificate authority domain validation, which normally requires placing a random value in a DNS TXT record. With that done, they pointed the affected domains at infrastructure they controlled, which allowed them to impersonate brands and serve arbitrary content to visitors.

The Hacker News pulled the certificates from Certificate Transparency logs on Oct. 7 and counted at least 12 covering seven domains: google.com.gh, youtube.com.gh, google.sl, google.com.sl, youtube.sl, google.as and youtube.as. By country that is two for .gh, six for .sl and four for .as. Let’s Encrypt issued 11 and ZeroSSL issued one, and all 12 were domain-validated certificates.

The logs show .gh certificates on Sept. 22, .sl on Sept. 25 and .as on Sept. 27, according to the same report. The first three were revoked on Sept. 26 and the remaining nine on Oct. 1. Google said it learned of the hijacks the week before its post.

Google blocked the certificates in Chrome through CRLSets, its emergency block list, and worked with the issuing authorities to revoke them. It then searched Certificate Transparency data and found other affected organizations, including “several leading global brands and widely used online services,” per BleepingComputer. Matthew McPherrin of Let’s Encrypt confirmed on the community forum: “Yes, certificates for Google and YouTube were issued, and have been revoked.”

Chrome users need to do nothing, Google said. That protection stops at Chrome, because CRLSets do not reliably cover other browsers and apps, per The Hacker News. Google also admitted the limits of its own search: “we cannot guarantee that our analysis identified every affected domain.”

Several things remain unreported. Nobody has named the attackers, Google’s post does not explain how the registries were compromised, and it does not say whether any certificate was used against real users.

How a DNS Change Became a Valid HTTPS Certificate

Certificate authorities do not know who you are. They check whether the person asking controls the domain, usually by asking for a value in DNS or a file on the site. Control the DNS and you pass. That is why a registry-level break produces certificates that browsers trust on sight.

The window matters too. The Hacker News reported that industry baseline rules currently let a certificate authority reuse a completed domain check for up to 200 days, dropping to 100 days in March 2027 and 10 days in March 2029. Let’s Encrypt reuses checks for 30 days and plans to cut that to 7 hours by 2028. A check an attacker passed during a hijack can keep minting certificates after you regain your DNS.

That is the reason Google pushes restrictive CAA records, the DNS entries that name which authorities may issue for a domain. Google’s team wrote: “While CAA can not prevent certificate issuance during an active DNS hijack, it provides a critical safeguard after DNS control is restored.” It also recommends monitoring Certificate Transparency logs for every domain you own, parked and regional ones included.

The sources disagree on where the break was. SC Media, relaying an Ars Technica report on Oct. 7, wrote that the incident “did not involve compromising the domain owners’ or DNS operators’ infrastructure” and compared it to the 2011 DigiNotar incident. Google’s post says the third-party registries were compromised. Google also said it has no reason to believe the certificate authorities did anything wrong. I’d treat the registry-compromise account as the primary-source version, since it comes from Google.

One more caution on scope. No outlet has reported stolen customer data or fraud against a store from these certificates. This is a confirmed hijack with unconfirmed damage. I wrote up a different trust-layer failure in September, when the Shop Pay checkout security bug surfaced.

What a Domain Hijack Costs a High-Ticket Store

My read: most stores are not directly exposed. If your store lives on a .com connected to Shopify, this breach touched registries you do not use. The risk that carries over is DNS control, and DNS control can be lost through a registrar account, a DNS host or a registry. Only the last one was hit this time, but the first two are where store owners tend to get careless.

High-ticket makes impersonation pay. Here is hypothetical math, not a reported figure. Say a store takes 12 orders a week at a $2,400 average order. If a hijack redirected half of them to a cloned checkout for one week, that is 6 orders and $14,400 of buyer money sent to someone else. Add the chargebacks, the refunds you chase and the support hours, and the loss lands well above the payments themselves. My fraud detection guide covers the order-side controls, but none of them help if the buyer never reaches your checkout.

The padlock stops proving anything. For years the advice was to look for https. A certificate issued after a DNS hijack passes that test. What a buyer can still verify out loud is a phone number, a named business and a real address, which is why I tell high-ticket stores to put a working support line on every page. A buyer who calls before wiring $3,000 is the buyer who catches a clone.

DNS also steers your email. An attacker who can edit your records can redirect mail and change the entries that authenticate your marketing email, so a hijack can hit the Klaviyo sending domain as well as the storefront. If you run business email on Google Workspace, the same logic applies to password resets for every tool tied to that address.

Scenarios, with thresholds. If you hold only one .com and it sits on Shopify, your exposure is the registrar login, and the checklist below takes under an hour. If you hold regional domains for international markets, or domains you parked and forgot, your exposure grows with each one, because each is a DNS record set nobody watches. If a domain ends in a small country-code extension, check who operates that registry before you build a brand on it. If you run more than one store, put every domain in a single inventory this week.

On Shopify, the platform’s own domain connection help page shows the TLS certificate being provisioned once the domain is connected. That handles issuance for you, but it does not protect the registrar account that controls where the domain points. For a new store, Shopify removes the certificate chore, though the registrar and DNS choices remain yours.

Ownership matters here as well. The domain should belong to the business, not to a personal account you also use for newsletters. I’d register it under the LLC, and my post on how long an LLC takes before launch shows the timeline. A real business address keeps your home out of the public record, and I laid out the options in getting a business address without renting an office. I’m not a lawyer, so run entity decisions past one.

I also compared two formation options in Bizee versus Northwest Registered Agent if you are choosing between them. Domain security is one layer of a stack that includes the entity, the address, the bank account and the payment backup plan. If you would rather not own all of that yourself, my team builds and runs high-ticket stores on a clean setup through the turnkey done-for-you service.

A hijacked domain is a store emergency, and most owners hear about it from a customer. Want one-on-one coaching to harden or fix your high-ticket store before that call comes? Get the coaching details →

Domain Lockdown Checklist for Store Owners This Week

Six actions, in the order I’d do them:

  1. Lock the registrar account. Turn on two-factor sign-in and the registrar lock, remove old logins and use a unique password. If your registrar offers neither, I’d move to Namecheap. Read my notes on what renewals cost there before you move. If you manage the account from coworking wifi, run a VPN.
  2. Build a domain inventory. List every domain you own, where its DNS is hosted, and what each one does. Delete records pointing at services you no longer use. If you bought a domain through a reseller, my breakdown of who you are really buying from at Domain.com shows why the registrar of record matters.
  3. Search Certificate Transparency logs for every domain you own. The Hacker News found these certificates with ctlogs.dev and Cert Spotter. Look for any certificate you did not request, and set up alerts through a monitoring service so the next one reaches you in hours instead of weeks.
  4. Add a CAA record, but verify your platform first. A CAA record that names the wrong authority blocks the right one from issuing for you. A June 24 thread on the Shopify community forum shows a merchant reporting that Shopify’s guidance listed ssl.com, while another member questioned whether the record is needed at all. Confirm the current requirement in Shopify’s help center before you save anything. If you host a WooCommerce store, check which authority your host uses; if you are choosing a host, Cloudways is one I’d look at.
  5. Secure the accounts attached to your domain. Your registrar, DNS host and business email all reset each other. Put hardware keys or app-based two-factor on the admin account, and run a VPN like Surfshark when you sign in away from home. Follow the security section in my Google Workspace walkthrough.
  6. Write a one-page response plan. List who calls the registrar, who posts a banner on the store and how you will tell customers. Know where to report a bad certificate: under the CA/Browser Forum baseline rules, per The Hacker News, a certificate authority must investigate a Certificate Problem Report and send initial findings within 24 hours. If you want a second set of eyes on your setup, book a call at my discovery page.

Frequently Asked Questions

Does this breach affect my Shopify store?
Only if your domain ends in .gh, .sl or .as, based on what Google and The Hacker News reported. The technique, though, works against any domain whose DNS an attacker controls, so the registrar and DNS steps above apply to everyone. My Shopify store security guide covers the rest of the store.

What is a CAA record?
It is a DNS entry that lists which certificate authorities may issue certificates for your domain. Google says a CAA record cannot stop issuance during an active hijack but helps after you regain control.

Should I add a CAA record to my Shopify domain?
Check Shopify’s current domain instructions first. A June 2026 community thread shows confusion over what value to enter, and a record that omits the authority your platform uses can block certificate issuance for your store. On WooCommerce, my guide to setting up Cloudways shows where the certificate settings live.

How do I check Certificate Transparency logs?
Search your domain in a public log search tool. The Hacker News used ctlogs.dev and Cert Spotter. Look for certificates you did not order, including on subdomains, parked domains and regional extensions.

What if I find a certificate I did not request?
File a Certificate Problem Report with the issuing authority, then lock down the registrar account and review your DNS records. The Hacker News reported that the baseline rules give the authority 24 hours to send initial findings. If you buy certificates outside your platform, SSLs.com is one seller, but a purchased certificate does not protect a hijacked DNS record.

Should the domain be registered to my LLC?
I’d say yes, so a compromised personal account or a partner dispute cannot take the store with it. The launch checklist for a high-ticket dropshipping business puts the entity and domain ownership near the top. My free beginner guide also walks through the setup order. Again, I’m not a lawyer.

Want my team to scale the store you already have, with the domain, DNS and checkout basics set up right? See the scaling service →

That is the news. Check your registrar login tonight, because that is the one step that costs nothing, and it closes the door the Ghana, Sierra Leone and American Samoa attackers used. Pick one domain, run the six steps, then repeat for the rest. Expect the first pass to take an hour and every later review to take minutes. Subscribe to the YouTube channel for daily breakdowns. More breaking news coming through the day.

Related Articles

If this was useful, these go deeper:

Free 1,000+ high-ticket niches list

Still deciding what to sell?

Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.

Free. Unsubscribe any time.