PKI Disasters Hall of Fame
Learn from the failures that shaped certificate security

Certificate Authorities have one job: be trustworthy. When they fail, the consequences ripple across the entire internet.
These case studies document the PKI disasters that led to browser distrust, company bankruptcies, and industry-wide policy changes. Each one carries lessons for anyone managing certificates today.
The Hall of Fame
Entrust Distrust
2024Pattern of compliance failures, refused to revoke
Lesson: Reputation doesn't protect you
Read Case StudySymantec Distrust
2017Mass mis-issuance, inadequate controls
Lesson: Volume doesn't equal trust
Read Case StudyWoSign/StartCom
2016Backdated certificates, lied to browsers
Lesson: Deception is fatal
Read Case StudyDigiNotar Breach
2011Hacked, fake Google certs, bankrupt in weeks
Lesson: Security failures kill
Read Case StudyTimeline of Trust Failures
CA next?
Why Study PKI Disasters?
Every CA distrust follows a pattern: small violations accumulate, warnings are ignored, browsers lose patience, customers scramble. The organizations that survive are the ones who learned from someone else's disaster - not their own.