A fraudulent google.com security certificate issued by Dutch certificate authority DigiNotar was discovered being used in Iran, revealing a serious breach at the company. Investigators found that attackers had issued false certificates for hundreds of domains.
What happened
- The intrusion began in mid-June 2011, and false certificates were in use for around two months before disclosure.
- An investigation by Fox-IT, known as the Black Tulip report, estimated that around 300,000 Iranian users were subject to interception attacks.
- Browser makers including Google, Mozilla, and Microsoft removed trust in DigiNotar, and the Dutch government took over management of its certificate operations, which had supported government services.
- DigiNotar was declared bankrupt in September 2011.
Why it mattered
The case exposed weaknesses in the web’s trust model and showed that a single compromised certificate authority could enable large-scale surveillance of encrypted traffic. It accelerated measures such as certificate transparency.
Lessons for organisations
Suppliers that underpin trust, such as certificate authorities and identity providers, need strong assurance and incident reporting. Report breaches promptly: delay significantly increased the harm here. Keep an inventory of the certificates you rely on so you can replace them quickly if a provider fails.
Sources: ENISA, CCDCOE Cyber Law Toolkit
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.