History

The 2011 Comodo Certificate Authority Breach

In March 2011, an attacker compromised a reseller account tied to Comodo, a major certificate authority, and used it to issue fraudulent certificates for several high-value domains, including Google, Yahoo, and Skype — certificates that would have been trusted by browsers by default, since they were signed by a legitimately trusted CA.

1 An attacker compromised a Comodo affiliate's systems Not Comodo's own core infrastructure directly, but a partnerreseller with issuance access 2 Fraudulent certificates were issued for major domains Including ones for large email and social media platforms —nine certificates in total 3 Comodo detected and revoked them relatively quickly Limiting, though not eliminating, the exposure window 4 The incident pushed browsers toward requiring Certificate Transparency A direct causal link between this exact kind of undetectedmis-issuance and CT's later mandatory rollout
How the Breach Unfolded

How it was caught

Comodo detected the unauthorized issuance relatively quickly and revoked the fraudulent certificates, and browser vendors pushed emergency updates to explicitly block them. The incident is frequently cited as part of the case for Certificate Transparency, which would later make this kind of unauthorized issuance detectable by anyone monitoring public logs, rather than depending on the CA itself catching it internally.

Its place in CA security history

The Comodo breach, alongside the more severe DigiNotar incident later the same year, marked a period when the industry's trust model came under real, public scrutiny — accelerating both technical countermeasures (Certificate Transparency) and stricter CA operational security requirements.

How the fraudulent certificates were in practice caught so quickly

Comodo's relatively fast detection compared to DigiNotar's much longer undetected compromise is often credited to better internal monitoring of unusual issuance patterns within Comodo's own systems — an early example of what would later become standard CA practice: actively watching for anomalous issuance activity rather than relying only on external detection or user reports.

Why this incident is often treated as a preview of DigiNotar's more severe failure

Security researchers and browser vendors frequently discuss the Comodo and DigiNotar breaches together, since they happened within months of the same year and shared broadly similar root causes — a compromised reseller or partner account used to issue fraudulent certificates. But Comodo's faster detection and much smaller scope meant it functioned more as an early warning sign, while DigiNotar's far more severe and prolonged compromise a few months later is what in fact forced systemic change.

Which specific domains were targeted in the fraudulent issuance

The Comodo breach's fraudulent certificates targeted several major, high-value domains including Google's Gmail service, Yahoo Mail, Skype, and Mozilla's own Firefox add-ons site — a pattern of targeting communication and identity-related services that researchers later noted was broadly consistent with intelligence-gathering motives rather than conventional financial cybercrime.

How the attacker's techniques were later connected to DigiNotar

Security researchers subsequently identified technical similarities between the tools and infrastructure used in the Comodo breach and the DigiNotar compromise later the same year, leading to a widely-held assessment that both incidents were likely perpetrated by the same individual or group — though full attribution was never definitively and publicly confirmed by an official body.

How Comodo's response differed from DigiNotar's eventual outcome

Unlike DigiNotar, Comodo survived the incident as a company and continued operating as a major CA — its faster detection, smaller scope, and cooperative response with browser vendors are generally credited as the key differences that let it retain sufficient trust to continue, in contrast to DigiNotar's total collapse a few months later.

Its role in accelerating the broader industry conversation about reseller account security

The Comodo breach exactly highlighted reseller account security as a distinct, often underappreciated attack surface within the certificate issuance ecosystem, since the compromise reportedly originated through a reseller's credentials rather than Comodo's own core infrastructure — prompting CAs industry-wide to reassess how tightly reseller and partner account permissions were scoped relative to core issuance systems.

Why it's frequently paired with DigiNotar in security curricula

Security courses covering PKI and certificate authority trust commonly present Comodo and DigiNotar together as a matched pair in particular because their differing outcomes, survival versus collapse, offer a clean comparative case study in what separates a contained security incident from an existential one for the organization involved.

Comodo's survival, contrasted with DigiNotar's collapse a few months later, offers a instructive before-and-after pairing for studying CA incident response.

Comments

Loading comments…