top of page

Two African Country Domains, One Global Trust Problem: What the .gh and .sl Registry Hijacks Mean for Everyone Who Uses the Web

21 hours ago
5 min read
The padlock in your browser is only as strong as the national registry above it. In October 2026, two of those registries in West Africa were breached.
The padlock in your browser is only as strong as the national registry above it. In October 2026, two of those registries in West Africa were breached.

Bottom line up front: attackers took control of the national internet registries of Ghana, Sierra Leone, and American Samoa, rewrote the address records that tell the internet where websites live, and used that control to obtain genuine security certificates for Google and other major brands. Google disclosed the incidents on October 6 and has blocked every counterfeit certificate it found. Nobody hacked Google. The attackers hacked the small registries beneath it, and that is the lesson. The security of every bank, ministry, and business that uses a .gh or .sl address now depends on institutions most citizens have never heard of.


What Happened, in Plain Terms

Every website address has two layers of trust behind it. The first is the Domain Name System, or DNS, the directory that converts a name like bank.com.gh into the numeric address of a server. The second is the certificate, the digital document that lets a browser display a padlock and confirm that the server really belongs to the bank. A certificate authority issues that document only after checking that the applicant controls the domain, and the usual way to check is to look at DNS.


The attackers understood that chain. According to Google's Chrome security team, they compromised the registries that operate the .gh, .sl, and .as country-code top-level domains, modified authoritative DNS records, and then applied for certificates covering several Google domains and domains belonging to other organizations. The certificate authorities checked DNS, saw records that pointed to the attackers, and issued the certificates. Google says it has no reason to believe the authorities did anything wrong. They followed the rules. The rules trusted a registry that had already been taken.


Google learned of the hijacks last week, blocked the certificates in Chrome, worked with the issuing authorities to revoke them for other browsers, and then used public Certificate Transparency logs to find and block additional certificates issued to what it called several leading global brands. It has not named the brands, the attackers, or the method used to breach the registries.

"Nobody hacked Google. The attackers hacked the small registries beneath it."

Why a Small Registry Is a Big Target

Country-code domains are run by national bodies. Sierra Leone's .sl is operated by Sierratel, the state telecommunications company. Ghana's .gh has been administered in-country since 1995 and has been the subject of a long-running ownership dispute between the original operator and the government's Ghana Domain Name Registry, which told ICANN in 2023 that redelegation remained unresolved. Google has not said how either registry was compromised, and OSRS draws no causal link between that dispute and the breach. The narrower point stands: a registry with contested ownership, a thin budget, and little public scrutiny is exactly the institution an adversary studies first.

Three features make such registries attractive:

  • Leverage. One registry controls every domain beneath it. The attackers did not need to breach a bank in Accra or a ministry in Freetown. Owning the registry meant owning the ability to impersonate all of them at once.

  • Global reach from a local base. A certificate for a Google domain obtained through .gh works anywhere in the world until it is revoked. The target does not have to be in Ghana. The weakness only has to be.

  • Slow detection. Google found the certificates because it monitors transparency logs around the clock. Most organizations in West Africa do not. A counterfeit certificate for a regional bank could sit unnoticed for weeks.

The historical precedent is DigiNotar. In 2011, a compromised Dutch certificate authority issued a fraudulent certificate for Google that was used to intercept the email of hundreds of thousands of users, most of them in Iran. That attack required breaking a certificate authority. This one did not. It required breaking a national registry, and there are more than 250 of them.


What a Counterfeit Certificate Lets an Attacker Do

For readers without a technical background, the practical risk is impersonation that looks completely legitimate. An attacker holding a valid certificate and control of DNS can:

  1. Redirect users to a fake login page that shows a genuine padlock, then harvest passwords and one-time codes.

  2. Sit between a user and a real service, reading or altering traffic that both sides believe is encrypted.

  3. Deliver malicious software updates that pass authenticity checks because the signing chain appears correct.


Google has not said whether any certificate was used before it was blocked. That question matters most for the organizations that are not Google. Google can block a certificate for its own domains in Chrome within hours. A Ghanaian bank or a Sierra Leonean ministry depends on the slower, browser-by-browser revocation process, and Google's own guidance is blunt on this point.

"Browser-side intervention should not be relied on to protect your users."

An Analyst's View: The Fix Is Governance, Not Just Code

Google's technical advice is sound. Monitor Certificate Transparency logs for every domain you own, including parked and regional ones. Publish Certification Authority Authorization records that restrict which authorities may issue certificates for your domains and by which methods. Those records cannot stop issuance during an active hijack, but they stop an attacker from reusing cached validation to mint new certificates after control is restored.


Nevertheless, the deeper problem is institutional. The attackers chose registries, and registries are run by governments and their contractors. Four steps follow:

  • Policymakers in Ghana, Sierra Leone, and Nigeria: Treat the national domain registry as critical infrastructure on the same footing as the power grid and the payment switch. Fund it, audit it, and resolve ownership disputes that leave accountability unclear. Nigeria's .ng registry was not named in this incident. That is no reason to assume it could not be.

  • Security agencies and law enforcement: Demand a public incident report from each affected registry within 90 days. Silence protects the attacker and tells every other registry operator that breaches carry no consequence.

  • Banks, telecoms, and government agencies on .gh and .sl: Review transparency logs for the past 90 days now. Any certificate you did not request is evidence.

  • Business leaders everywhere: Ask your security team two questions this week. Do we monitor certificate issuance for all of our domains? Do we have CAA records in place? If the answer to either is no, you are relying on Google to notice your problem for you.


The Bottom Line

The internet's trust system assumes that the people who run national registries are secure. Three of them were not, and two of them are in West Africa. The attackers walked away with genuine certificates for some of the world's largest brands without touching those brands' systems. Google contained the damage it could see. The damage it could not see is the part that should concern every organization with a .gh or .sl address, and every government that has never asked who runs its registry, how it is funded, and who would know if it were breached.


OSRS can help. OGUN Security Research and Strategic Consulting provides critical infrastructure risk assessments, DNS and certificate monitoring programs, incident readiness reviews, and strategic advisory services for government, law enforcement, and private-sector leaders operating in Nigeria and across Africa. Contact us to schedule a briefing or a domain security assessment for your organization.


Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.


About the Author

Dr. Sunday Oludare Ogunlana is the Founder and CEO of OGUN Security Research and Strategic Consulting LLC, a Professor of Cybersecurity, a national security scholar, and a television commentator. He advises government, law enforcement, academic, and private-sector organizations on security strategy and serves on advisory bodies including the Global Alternative Agenda, the Council for African Security Affairs, and the African Security Forum.


Intelligence. Protection. Strategy. www.ogunsecurity.com

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page