DigiNotar, a Dutch certificate authority, was compromised and used to issue at least 531 fraudulent SSL certificates for 344 domains, including google.com, enabling spoofing and man-in-the-middle attacks against supposedly secure services. Reporting indicated the fake Google certificate was likely used to intercept Gmail traffic from users in Iran, potentially exposing roughly 300,000 accounts and putting dissidents at risk. The breach was publicly linked to the actor who had claimed responsibility for the earlier Comodo certificate fraud, and it intensified criticism of the certificate authority trust model as incapable of resisting nation-state abuse.
The fallout spread quickly across browsers, operating systems, and government services. Google, Microsoft, and Mozilla moved to distrust DigiNotar certificates, while Microsoft issued advisory 2607712 and updates including KB2607712 and KB2616676 to place DigiNotar certificates in the Windows Untrusted Certificate Store; Safari users were reported to remain exposed for a time. In the Netherlands, the government took over DigiNotar’s operations after investigators found severe security failures, warned that it could not guarantee the safety of its own websites, and shifted trust for public-sector certificates as DigiNotar’s business collapsed into bankruptcy.

See attribution, scope, and your downstream exposure.
14 events from the most recent confirmed update back to the earliest known activity.
Following the collapse of trust in DigiNotar, regulators required revocation of all certificates issued by the company. This effectively ended DigiNotar's certificate authority business.
After losing browser and government trust and seeing its certificate authority business collapse, DigiNotar filed for voluntary bankruptcy in September 2011. The filing marked the final corporate fallout from the breach.
Microsoft rereleased KB2616676 after discovering the earlier package did not fully include certificates from prior updates on Windows XP and Windows Server 2003. The rerelease corrected the trust-removal coverage for those platforms.
Microsoft replaced KB2607712 with KB2616676 to continue removing trust in DigiNotar certificates across Windows systems. The company urged users to install the newer update immediately.
As the breach disrupted trust in government PKI services, the Dutch government took over DigiNotar's operations. Authorities also warned they could no longer guarantee the security of government websites relying on DigiNotar certificates.
Microsoft issued security update KB2607712 to add DigiNotar certificates to the Windows Untrusted Certificate Store. The update was intended to protect supported Windows systems and Internet Explorer users from active attacks using fraudulent DigiNotar certificates.
A hacker previously tied to the Comodo certificate fraud publicly claimed to have also breached DigiNotar and other certificate authorities, including GlobalSign. The claim influenced public attribution of the incident toward the same Iranian actor.
Subsequent investigation found the breach was far worse than initially disclosed: 531 fraudulent certificates had been issued for 344 domain names, and DigiNotar's internal security was severely deficient. The findings deepened the trust crisis around the company.
Google, Microsoft, and Mozilla moved to distrust DigiNotar certificates as the scope of the breach became clearer. Ars Technica also reported that Safari users remained susceptible because Apple had not yet pushed equivalent protections.
Researchers and media reports said the rogue google.com certificate could have been used to monitor dissidents and steal credentials from users in Iran, potentially affecting hundreds of thousands of Gmail accounts. The case intensified criticism of the certificate authority trust model.
Microsoft updated its Certificate Trust List to remove trust from at least one DigiNotar root after learning a fraudulent DigiNotar certificate was being used in active attacks. The company warned the issue enabled spoofing, phishing, and man-in-the-middle attacks.
In August 2011, DigiNotar disclosed that it had been breached and had fraudulently issued SSL certificates, including one for Google. The disclosure triggered broader scrutiny of the certificate authority's security and trustworthiness.
Google released a Chrome update with certificate pinning protection that helped block misuse of the fraudulent DigiNotar google.com certificate. This reduced exposure for Chrome users compared with other browsers.
DigiNotar issued a rogue SSL certificate for google.com, later linked to man-in-the-middle attacks against Google services. Reporting said the certificate was created on 2011-07-10 and was particularly dangerous for users in Iran.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
technet.microsoft.com
Open sourcespectrum.ieee.org
Open sourcearstechnica.com
Open sourcearstechnica.com
Open sourcetheguardian.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.