1
Published signals
currently linked to this company
Company intelligence
digicert.com
This company page brings together public reporting currently associated with Digicert. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
1
recent published signals
1
recent published signals
1
confidence classifications
July 25, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Digicert. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
DigiCert's security incident in April 2026 has been attributed to CylindricalCanine, a subgroup of the China-linked cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group). The attackers compromised a support employee's device using malware delivered via a phishing lure disguised as a screenshot or document sent through DigiCert's support-ticket workflow. This intrusion granted the threat actors access to initialization codes for customers renewing code-signing certificates. By intercepting these codes, the attackers were able to obtain 27 fraudulent code-signing certificates, which were then used to sign malware, including the "Zong Stealer" campaign. DigiCert identified the incident through third-party reports of certificates being used in malware and subsequently revoked 60 certificates by April 17, with 27 explicitly linked to the attackers. The company emphasized that its root certificates were never compromised, and the breach was limited to a finite set of certificates. DigiCert has since blocked high-risk file types at ingestion, removed malicious files from Salesforce cases and chat records, and is working on sandboxing controls for inbound support attachments.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Digicert.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.