Domain Hijacking Is a Warning About the Internet’s Hidden Trust Layers
According to The Hacker News, attackers hijacked three country-code top-level domains — .gh, .sl, and .as — and used that access to obtain HTTPS certificates for Google domains. Google’s own systems were not breached, but the certificates were still revoked and blocked in Chrome.
This matters because an HTTPS certificate tells your browser that a website is genuine. If an attacker can get a certificate for a domain they do not control, they can intercept or read private data that people send to that site. This is not just a Google problem. It is a reminder that the internet’s trust system can be attacked from unexpected angles.
The Bigger Picture: Why This Is a Serious Cyber Threat
Most small businesses focus on firewalls, passwords, and backup software. That is reasonable, but this attack shows that cyber threats can also come from the domain system that makes websites work. Domain names and certificates are the invisible plumbing of the internet, and attackers are paying more attention to that plumbing.
A hijacked domain or a fake certificate can turn into a data breach very quickly. Customers may type your real web address, see the padlock icon, and still be sending their details to a criminal. The risk is not limited to large technology companies. Any business that manages a domain could face this kind of issue if a registry, registrar, or certificate authority is compromised.
What This Means for Australian SMBs
Australian small and mid-sized businesses often own multiple domain names, including parked domains or older country-specific versions. If attackers target those domains, a stolen certificate could be used to create convincing phishing pages that look like your business. Your customers would not know the difference, and your brand could suffer.
The good news is that you do not need to be a large company to take sensible precautions. Domain security is not expensive, but it does require attention. The businesses that take these steps are far less likely to become the next headline about a cyber attack.
What You Can Do Now
- Set up certificate transparency monitoring for every domain your business owns, including unused and parked domains.
- Publish strict CAA records that name exactly which certificate authorities are allowed to issue certificates for your domains.
- Use multi-factor authentication on every account related to your domain registrar and DNS provider.
- Enable DNSSEC if your registrar and DNS provider support it, so the DNS records that point to your website are harder to tamper with.
- Review your list of domain names regularly and remove anything you no longer use.
These actions will not stop every attack, but they reduce the chances