type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [incident, supply-chain, certificate-authority] ยท confidence: medium ยท affected_sectors: [technology, government, finance] ยท au_impact: false
DigiCert Breach (April 2026)
In April 2026, DigiCert โ one of the world's largest Certificate Authorities (CAs) โ suffered a security incident in which attackers stole code-signing certificates intended for customers.
Timeline
| Date | Event |
|---|---|
| April 2026 | Security incident occurs at DigiCert |
| July 17, 2026 | Expel researchers attribute the breach to CylindricalCanine (GoldenEyeDog subgroup) |
Attribution
Expel researchers attributed the incident to Cylindrical Canine, a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). (raw/digests/Cyber-Digest-2026-07-18)
Tactics
- Attackers used a modified Gh0st RAT to compromise a DigiCert support member's device
- Stole code-signing certificates that were intended for DigiCert customers
- The breach targeted the CA's internal support infrastructure, not the certificate issuance pipeline itself
Significance
Code-signing certificate theft from a major CA enables threat actors to sign malware with trusted certificates, bypassing OS and security software trust checks. This represents a supply chain attack at the internet trust infrastructure layer.
Related Pages
- Cylindrical Canine โ The threat actor subgroup attributed to the breach
- Intellexa Predator โ Another trust/espionage supply chain (spyware)
- Progress Software โ Software supply chain incidents (MOVEit, etc.)
Note: DigiCert has not independently confirmed the attribution. This assessment is based solely on Expel's research (Tier 2 source).