← DigiCert cases
Bugzilla #2033170 Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Problem Reporting Failure

DigiCert self-reported security incident involving compromised support endpoints and misuse of code signing initialization codes

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert opened this case to disclose a security incident affecting its support operations and code signing certificate delivery workflow. The incident began when a threat actor sent a malicious file through a customer support channel and compromised two support analyst endpoints, then used the support portal to obtain initialization codes for approved EV Code Signing certificate orders. DigiCert reported that it revoked 60 affected certificates, cancelled pending orders, and set the revocation date to the issuance date for the identified certificates. The company also said it reviewed support chat logs, outbound communications, and data access, and found no evidence that customer-related data was misused. In later updates, DigiCert said all action items were complete, including restricting initialization-code access to authorized customer account admins and expanding logging and monitoring for file delivery. DigiCert posted a closure summary on 2026-07-09, and CCADB issued a final call for comments on 2026-07-10 before the case was expected to close.

Model: gpt-5.4-mini Generated: 2026-06-13 11:49 UTC Revised: 2026-07-26 06:01 UTC Confidence: 0.98 19 comments
Chronology
  1. A threat actor delivered a malicious file through DigiCert support and began the compromise that led to access to code signing initialization codes.
  2. DigiCert detected and contained the first compromised support endpoint.
  3. Further investigation identified a second compromised endpoint and affected EV Code Signing certificate orders.
  4. DigiCert began revoking certificates potentially affected by the incident.
  5. DigiCert completed revocation of the identified affected certificates and cancelled pending orders.
  6. DigiCert said it had completed its review of code signing delivery workflows and limited initialization code access to authorized customer account admins.
  7. DigiCert said expanded logging and monitoring for file delivery had been completed across all support channels.
  8. DigiCert said all proxy access was read-only, sensitive fields were masked, and all action items in the report were complete.
  9. DigiCert posted a report closure summary stating that all action items were completed and requesting closure of the report.
Thread Activity
  1. DigiCert — DigiCert filed a preliminary incident report describing the support compromise, certificate misuse, and revocation actions.
  2. DigiCert — DigiCert posted the full incident report with details on the compromised endpoints, affected certificates, and remediation steps.
  3. Community commenter — A commenter asked follow-up questions about infrastructure overlap, internal process familiarity, and the timeline of compromised certificate use.
  4. DigiCert — DigiCert answered the follow-up questions, including that it found no infrastructure overlap with the initial support chat or C2 activity and no evidence of customer data misuse.
  5. DigiCert — DigiCert posted an action-item update showing several remediation tasks completed and others ongoing.
  6. DigiCert — DigiCert said it had completed its review of code signing delivery workflows and limited initialization code access to authorized customer account admins.
  7. DigiCert — DigiCert said expanded logging and monitoring for file delivery had been completed across all support channels.
  8. DigiCert — DigiCert said all proxy access was read-only, sensitive fields were masked, and all action items in the report were complete.
  9. DigiCert — DigiCert posted a report closure summary describing the incident, root causes, remediation, and a request for closure.
  10. CCADB representative — CCADB issued a final call for comments or questions and said the report would be closed around 2026-07-16.
Participants
DigiCert Community commenter Sectigo CCADB representative
Similar Local Cases
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 100% similar
DigiCert: Several non-functioning AIA URLs
#1974539 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-27 · Closed 2025-10-09 · 95% similar
DigiCert: DCV logging issue
#1950144 RESOLVED Incident Self Reported Incident Opened 2025-02-24 · Closed 2026-06-11 · 94% similar
DigiCert: Threat of legal action to stifle Bugzilla discourse
#2014610 RESOLVED Self Reported Incident Incident Opened 2026-02-05 · Closed 2026-04-11 · 86% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 86% similar
DigiCert: Random value in CNAME without underscore prefix
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 86% similar
Netlock: unspecifed revocation code (0) in CRL
#2016672 RESOLVED Incident Revocation Issue Opened 2026-02-13 · Closed 2026-03-30 · 86% similar
certSIGN: certificates with delayed SCT signature
#2055539 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Opened By Ca Opened 2026-07-16 Still Open · 85% similar
DigiCert: Delayed availability of OCSP responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action