Attackers took over the domain systems for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as) and used them to get real HTTPS certificates for Google and other major brands.
They did not break into Google or the certificate authorities. They changed the official DNS records those authorities check when deciding who controls a domain. Once the checks passed, the authorities issued valid certificates that could make a fake site look trusted.
Google disclosed the incidents on October 6. Chrome is blocking the unauthorized certificates it has found, and the certificates covering Google’s own domains have been revoked. Google says it may not have found every affected domain, and the Chrome block does not protect people using other browsers.
Any site ending in .gh, .sl, or .as was potentially at risk. Owners of those domains are being told to check recent certificate records for unexpected issuance.