Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [incident, supply-chain, certificate-authority] ยท confidence: medium ยท affected_sectors: [technology, government, finance] ยท au_impact: false

DigiCert Breach (April 2026)

In April 2026, DigiCert โ€” one of the world's largest Certificate Authorities (CAs) โ€” suffered a security incident in which attackers stole code-signing certificates intended for customers.

Timeline

Date Event
April 2026 Security incident occurs at DigiCert
July 17, 2026 Expel researchers attribute the breach to CylindricalCanine (GoldenEyeDog subgroup)

Attribution

Expel researchers attributed the incident to Cylindrical Canine, a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). (raw/digests/Cyber-Digest-2026-07-18)

Tactics

  • Attackers used a modified Gh0st RAT to compromise a DigiCert support member's device
  • Stole code-signing certificates that were intended for DigiCert customers
  • The breach targeted the CA's internal support infrastructure, not the certificate issuance pipeline itself

Significance

Code-signing certificate theft from a major CA enables threat actors to sign malware with trusted certificates, bypassing OS and security software trust checks. This represents a supply chain attack at the internet trust infrastructure layer.

Related Pages

Note: DigiCert has not independently confirmed the attribution. This assessment is based solely on Expel's research (Tier 2 source).