GlobalSign said it will stop issuing Extended Validation (EV) TLS/SSL certificates and will revoke a subset of existing SSL certificates that failed to meet CA/Browser Forum validation requirements. The company said the affected revocations stem from shortcomings in its own validation process rather than customer actions, particularly around verifying organizations against official registration records using qualified independent information sources, and warned customers to replace impacted certificates to avoid service disruption.
The move reflects broader changes in browser behavior and industry standards that have reduced the practical value of EV certificates while tightening compliance expectations for certificate authorities. GlobalSign said existing EV certificates not affected by the compliance issue will remain valid until expiration, and it is directing customers toward other certificate options for website and IT infrastructure protection as CA/Browser Forum rule changes continue to reshape organizational validation practices.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
GlobalSign said it will stop issuing Extended Validation TLS/SSL certificates, citing evolving industry practices and CA/Browser Forum requirements. The company said the change takes effect on June 13 at 04:10 MSK, while existing EV certificates will remain valid until they expire.
GlobalSign announced that some SSL certificates would be revoked because its validation process did not comply with CA/Browser Forum requirements. The company said affected certificates were to be revoked on the 13th at 04:10 MSK and urged customers to replace them to avoid disruption.
The references state that CA/Browser Forum requirements for EV validation were revised in 2022, with later updates in 2024 and 2026 affecting how certificate authorities verify organization information and EV fields.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
cabforum.org
Open sourceopennet.me
Open sourceopennet.ru
Open sourcecabforum.org
Open sourcecabforum.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.