Hackers compromise operators of three country-code top-level domain registries—.gh (Ghana), .sl (Sierra Leone) and .as (American Samoa)—then use that access to obtain unauthorized HTTPS certificates for multiple Google domains. With the certificates, attackers can impersonate legitimate sites over encrypted connections.
Google says its own systems are not breached, but the incidents place any domains under the affected ccTLD endings at risk because attackers modify authoritative DNS records. Outlets report that the attackers first take control of the third-party ccTLD operators and then alter DNS control in order to satisfy certificate issuance requirements.
Different coverage focuses on the same sequence: registry/operator compromise, DNS record changes, and fraudulent certificate issuance. One report emphasizes the direct impact on Google domains, while another highlights that domains run by other large organizations can also be affected, given the certificate and DNS control mechanism.