· · Single source ·Updated

Hackers stole fake TLS certificates for Google and other major internet services

Security researchers report that attackers compromised three domain registries to generate unauthorized certificates for Google and other large organizations.

Hackers obtain counterfeit TLS certificates for Google and other large services
File photo Hackers obtain counterfeit TLS certificates for Google and other large services Photo: Ars Technica

Attackers targeted domain registries

Researchers discovered that hackers gained access to three separate domain registration authorities. This breach allowed the criminals to issue counterfeit security certificates without permission.

Certificates issued for big firms

The stolen credentials were used to create valid-looking certificates for Google and several other major tech companies. These fake certificates could have been used to intercept encrypted traffic from users.

Investigation into the breach

Security experts are currently analyzing how the registries were accessed by the threat actors. The incident highlights vulnerabilities in the systems that manage digital identity verification online.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.