DigiCert self-reported security incident involving compromised support endpoints and misuse of code signing initialization codes
DigiCert opened this case to disclose a security incident affecting its support operations and code signing certificate delivery workflow. The incident began when a threat actor sent a malicious file through a customer support channel and compromised two support analyst endpoints, then used the support portal to obtain initialization codes for approved EV Code Signing certificate orders. DigiCert reported that it revoked 60 affected certificates, cancelled pending orders, and set the revocation date to the issuance date for the identified certificates. The company also said it reviewed support chat logs, outbound communications, and data access, and found no evidence that customer-related data was misused. In later updates, DigiCert said all action items were complete, including restricting initialization-code access to authorized customer account admins and expanding logging and monitoring for file delivery. DigiCert posted a closure summary on 2026-07-09, and CCADB issued a final call for comments on 2026-07-10 before the case was expected to close.
- A threat actor delivered a malicious file through DigiCert support and began the compromise that led to access to code signing initialization codes.
- DigiCert detected and contained the first compromised support endpoint.
- Further investigation identified a second compromised endpoint and affected EV Code Signing certificate orders.
- DigiCert began revoking certificates potentially affected by the incident.
- DigiCert completed revocation of the identified affected certificates and cancelled pending orders.
- DigiCert said it had completed its review of code signing delivery workflows and limited initialization code access to authorized customer account admins.
- DigiCert said expanded logging and monitoring for file delivery had been completed across all support channels.
- DigiCert said all proxy access was read-only, sensitive fields were masked, and all action items in the report were complete.
- DigiCert posted a report closure summary stating that all action items were completed and requesting closure of the report.
- DigiCert — DigiCert filed a preliminary incident report describing the support compromise, certificate misuse, and revocation actions.
- DigiCert — DigiCert posted the full incident report with details on the compromised endpoints, affected certificates, and remediation steps.
- Community commenter — A commenter asked follow-up questions about infrastructure overlap, internal process familiarity, and the timeline of compromised certificate use.
- DigiCert — DigiCert answered the follow-up questions, including that it found no infrastructure overlap with the initial support chat or C2 activity and no evidence of customer data misuse.
- DigiCert — DigiCert posted an action-item update showing several remediation tasks completed and others ongoing.
- DigiCert — DigiCert said it had completed its review of code signing delivery workflows and limited initialization code access to authorized customer account admins.
- DigiCert — DigiCert said expanded logging and monitoring for file delivery had been completed across all support channels.
- DigiCert — DigiCert said all proxy access was read-only, sensitive fields were masked, and all action items in the report were complete.
- DigiCert — DigiCert posted a report closure summary describing the incident, root causes, remediation, and a request for closure.
- CCADB representative — CCADB issued a final call for comments or questions and said the report would be closed around 2026-07-16.