The top-level domains of Ghana, Sierra Leone, and American Samoa were hijacked by hackers who manipulated DNS records by taking control of domain name registries and used these records to apply for and obtain TLS certificates. After successfully acquiring the certificates, the hackers redirected the domains to their own servers for traffic hijacking and decryption. Google's security team revealed that unauthorized TLS certificates had appeared for the domain names of websites belonging to multiple organizations, including Google, and had urgently blocked the relevant certificates through Chrome's CRLSet mechanism.
