Google reported that it detected and blocked an attempted man-in-the-middle campaign after attackers used a fraudulent certificate for google.com, allowing interception of users' connections to Google services. The certificate was traced to Dutch certificate authority DigiNotar, whose systems had been compromised, and the attack reportedly affected hundreds of thousands of users, primarily in Iran. Google said Chrome's built-in certificate checks helped expose the issue after a user encountered Gmail certificate warnings.
Subsequent reporting found that attackers exploited unpatched DigiNotar systems and generated at least 531 rogue certificates, turning the breach into a major failure of the internet's certificate trust model. The Dutch government assumed control of DigiNotar, browser vendors revoked trust in its certificates, and the company ultimately collapsed. The incident became a catalyst for stronger certificate authority controls and broader adoption of defenses including certificate pinning and Certificate Transparency.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
Google publicly said it had detected and rejected a fraudulent certificate for Google services and attributed the issue to a compromise of DigiNotar. Google said about 298,140 affected IPs had been seen, roughly 95 percent of them in Iran.
An Iranian user using the alias alibo reported that Gmail was inaccessible from Iran unless a VPN was used, helping expose the fraudulent certificate activity.
In August 2011, thousands of Iranian users were redirected to fraudulent Google-looking sites using a rogue DigiNotar google.com certificate in an apparent effort to access Gmail communications.
DigiNotar discovered that some signed certificates were missing from its logs, then revoked the discovered rogue certificates and began an internal investigation.
The intruder issued the first fraudulent certificate via DigiNotar, marking the start of rogue certificate generation from the compromised CA.
By the end of July 2011, DigiNotar incorrectly believed it had contained the compromise, even though attackers continued to abuse rogue certificates.
Attackers exploited unpatched software on DigiNotar web servers to obtain an initial foothold in the certificate authority's environment.
By the end of the summer of 2011, the attacker had issued 531 rogue certificates for domains including google.com, microsoft.com, aol.com, cia.gov, and mossad.gov.il.
Within a month of the public disclosure, the Dutch government took over DigiNotar and commissioned Fox-IT to investigate the breach.
Following the fallout from the compromise and loss of trust, DigiNotar eventually declared bankruptcy and ceased operations.
After the compromise became public, browser vendors moved to revoke trust in DigiNotar certificates, including Mozilla shipping changes to block affected certificates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.