Hackers Forge TLS Certificates for Google After Registry Compromise
Security·October 7, 2026

A significant security incident has exposed a dangerous vulnerability in internet infrastructure after hackers successfully compromised three domain registries and used the breach to obtain forged TLS certificates for Google and other major services.
The compromised registries allowed attackers to bypass the standard certificate issuance process by gaining direct control over the registrations they targeted. By spoofing legitimate TLS certificates, the threat actors could potentially intercept encrypted traffic intended for Google and other targeted companies, creating a pathway for man-in-the-middle attacks that could compromise user data and sessions.
TLS certificates form the foundation of secure internet communication, cryptographically verifying that a website is authentic. When these certificates are forged, users connecting to malicious servers receive what appears to be a legitimate security connection. This type of attack is particularly dangerous because it operates below the level of most security tools and user awareness.
The breach of multiple domain registries represents a significant escalation in certificate-based attacks. Rather than exploiting individual company systems, the attackers targeted the registrar level where domain ownership is centrally managed. This approach creates a far broader attack surface, potentially affecting thousands of domains registered with the compromised services.
Security researchers have begun notifying affected organizations and registries are likely conducting forensic investigations to determine the full scope of compromise and how long unauthorized access persisted. Domain registries typically serve as the first line of defense for domain security, making this breach particularly troubling for the broader trust infrastructure of the web.
The incident underscores ongoing concerns about certificate issuance security and has likely triggered discussions among browser makers, certificate authorities, and domain registries about stricter verification procedures and monitoring systems to prevent similar incidents.
Reporting based on an external source.