This database collects every publicly documented SSL and TLS certificate expiry or misuse incident involving a named organization, a confirmed certificate root cause, and documented scope of impact. Entries are sourced from official post-mortems, confirmed company statements, and named media reports. Financial impact figures are reproduced only when attributed to a named source. For forensic narrative analysis and root cause detail, see The SSL Certificate Expiry Graveyard and The SSL Hall of Shame (companion articles). For financial cost modeling methodology, see The SSL Hall of Shame.
| Organization | Date | Duration | Scope / Users Affected | Financial Impact | Root Cause | CA Involved | Primary Source |
| Comodo CA (reseller compromise) | Mar 2011 | Hours (fraudulent certs active until revoked) | Nine fraudulent certificates issued for google.com, yahoo.com, live.com, skype.com, and others. Three domains confirmed used in attacks. | Not quantified. Rapid revocation limited damage. | Comodo reseller accounts in Iran, Turkey, and Czech Republic compromised. Fraudulent OV certs issued without proper validation. | Comodo | Comodo official statement March 23 2011; EFF analysis; F-Secure |
| DigiNotar / O2 / Dutch Government | Jun–Sep 2011 | ~2 months (fraudulent certs active); 24 days company to bankruptcy after disclosure | 531 fraudulent certificates. ~300,000 Iranian Gmail users intercepted. Dutch government digital services collapsed when roots revoked. | £100M+ compensation sought by O2 from Ericsson for a related CA cert incident; DigiNotar itself: complete bankruptcy and liquidation. | Intrusion via DotNetNuke vulnerability on DMZ server. Lateral movement to all 8 CA servers. No intrusion detection. 6-week disclosure failure. | DigiNotar (Comodo Group) | Fox-IT Black Tulip Report 2012; ENISA Operation Black Tulip 2011; Wired (K. Zetter) Sep 2011 |
| Microsoft Azure Storage | Feb 22, 2013 | ~8 hours | Azure Storage service in multiple regions. Enterprise customers unable to access blob, queue, and table storage. | Not disclosed. Enterprise customer SLA credits issued. Azure at ~$1.5B ARR at the time. | Expired SSL certificate on Azure storage service endpoints. Monitoring did not detect the expiry before customer impact. | Microsoft internal CA | Microsoft Azure Status History; ZDNet February 2013; InfoQ February 2013 |
| Apple Push Notification Service | Jul 17, 2015 | ~12 hours | Millions of iOS and macOS app users globally. Apps unable to receive push notifications. | Not disclosed. Significant developer and brand impact for any app dependent on time-sensitive push notifications. | Expired SSL certificate on Apple’s APNS infrastructure. Apple confirmed certificate expiry as root cause. | Apple internal CA | Apple Developer Forums July 2015; TechCrunch July 17 2015 |
| LinkedIn (lnkd.in link shortener) | 2016 | Brief; certificate replaced after reports | Desktop users receiving SSL connection error on all lnkd.in shortened links | Not quantified. Brand and usability impact on high-volume link shortener used across LinkedIn’s own platform. | Expired TLS certificate on lnkd.in subdomain. Second certificate incident for LinkedIn in approximately 2 years. | Comodo/Sectigo | The SSL Store blog 2016; Encryption Consulting analysis |
| Ericsson / O2 UK / SoftBank Japan | Dec 6, 2018 | ~24 hours (O2 UK); ~4.5 hours (SoftBank Japan) | ~32 million O2 UK subscribers; tens of millions in Japan; 11 countries affected. | O2 sought up to £100M compensation from Ericsson. O2 credited 2 days’ service to all pay-monthly subscribers. | Expired software certificate in Ericsson SGSN-MME network nodes running specific software versions. Embedded in telecom equipment, not a web server certificate. | Ericsson internal PKI | Ericsson RCA Statement Dec 2018; ITPro; Daily Telegraph; TechRadar |
| US Federal Government (80+ .gov sites) | Jan 2019 (35-day shutdown) | Days to weeks per site; some for duration of 35-day shutdown | NASA subdomains, DOJ, Court of Appeals, payment portals, remote access services. 130+ sites eventually affected. | Not quantified (government). Sites on HSTS preload became completely inaccessible, not just insecure. Cybersecurity risk to payment portals documented. | 400,000 furloughed federal workers could not renew certificates during government shutdown. No emergency renewal authorization in place. | Let’s Encrypt, DigiCert, others (various) | Netcraft January 2019; BleepingComputer January 14 2019; GCN; Dark Reading |
| Microsoft Teams | Feb 3, 2020 | ~3 hours | 20 million daily active users globally. All users unable to log in. Microsoft’s own operations affected. | Not disclosed. Enterprise SLA credits. Teams competing with Slack for enterprise adoption; significant brand event. | Authentication certificate expired on Teams infrastructure. @MSFT365Status confirmed: ‘An authentication certificate has expired.’ | Microsoft internal CA | Microsoft 365 Status Twitter Feb 3 2020; Engadget; Inc.com; SOCRadar |
| Spotify | Aug 19, 2020 | ~1 hour | Global Spotify users. ~4,000 #SpotifyDown Twitter mentions in first hour. Early morning North America, business hours Europe. | Not disclosed. ThousandEyes estimated limited revenue impact given off-peak timing in North America. | Expired TLS certificate on wg.spotify.com subdomain. | Let’s Encrypt | ThousandEyes August 19 2020; Keyfactor post-mortem analysis |
| LinkedIn (lnkd.in, second incident) | circa 2020 | Brief | Desktop users receiving SSL error on lnkd.in links. Second recurrence within approx. 2-year period. | Not quantified. Recurrence suggests systematic certificate monitoring gap, not isolated incident. | Expired TLS certificate on lnkd.in link shortener subdomain. Same subdomain as 2016 incident. | Comodo/Sectigo | The SSL Store blog; Encryption Consulting |
| Google Voice | Feb 15–16, 2021 | ~4 hours | Global Google Voice users. VoIP calls failed entirely for duration. | Not disclosed. | Failure to update certificate configurations caused active certificate to expire. Google Root Cause Analysis confirmed certificate expiry as cause. | Google Trust Services | Encryption Consulting; Sectigo blog Feb 2026; Google RCA |
| Epic Games (Fortnite, Rocket League, Epic Games Store, Epic Online Services) | Apr 6, 2021 | ~5.5 hours total (certificate renewed within 37 min; cascading failures extended outage) | All Fortnite, Rocket League, Houseparty, Epic Online Services, and Epic Games Store users globally. Login, purchasing, and live gameplay affected. 25 staff directly engaged in recovery. | Not disclosed in dollar terms. 25 staff plus Player Support, Community, Engineering, and Production teams. FY2021 Epic revenue ~$5.75B/yr. | Wildcard TLS certificate expired on internal DNS zone deployed across hundreds of backend services. Monitoring did not cover the specific certificate. Cascading secondary failures extended outage beyond initial certificate renewal. | Let’s Encrypt | Epic Games public post-mortem (epicgames.com); Keyfactor; AppViewX |
| Spotify / Megaphone (podcast platform) | May 30, 2022 | ~9 hours | All Megaphone podcast publishers (CMS inaccessible) and podcast listeners across Megaphone-hosted shows globally. | Not disclosed. Revenue impact to podcast advertising dependent on Megaphone distribution. | SSL certificate expired on Megaphone podcast platform (acquired by Spotify 2020). Spotify spokesperson confirmed to NPR. | Unknown | NPR May 31 2022; Sectigo blog; Wyoming Public Media |
| Microsoft WinGet CDN | 2023 | Not specified | Users attempting to install or upgrade packages via Windows Package Manager (winget). | Not disclosed. Developer productivity affected at scale. | Expired SSL certificate on WinGet CDN endpoint disrupted package installation and upgrade operations. | Microsoft / CDN provider | Red Sift blog April 2026; Certera blog May 2025 |
| Microsoft / Spotify Clock Integration (Windows 11) | Feb 2023 (unresolved for months) | Months | Windows 11 users who had linked Spotify to the Clock app for focus sessions. Feature integration non-functional. | Not disclosed. Feature removed from integration catalog for extended period. | Certificate expiry on the oATH header submitted to Spotify’s API made the integration invalid. Microsoft responsible for the expired certificate. | Microsoft internal CA | Certera blog May 2025 |
| DigiCert (support channel compromise) | Apr 2026 | Discovered April 2026 | Two EV Code Signing certificates used to sign Zhong Stealer malware. 60 certificates revoked. Attackers breached support chat 27 times before detection. | 60 certificates revoked. Significant brand impact for world’s largest commercial CA. Downstream malware distribution from fraudulent certificates. | Social engineering of DigiCert support team through chat platform vulnerability. Attackers impersonated a customer and extracted EV Code Signing certificates. | DigiCert | News4Hackers May 2026; DigiCert revocation notices April 2026 |
Inclusion Criteria and Update Policy
An incident is included in this database when all three of the following conditions are met:
- Named organization: the affected company or organization is publicly identified
- Confirmed root cause: a certificate expiry, mis-issuance, or configuration failure is confirmed as the root cause by an official post-mortem, company statement, or credible named media report
- Documented scope: the duration or number of affected users is reported from a named source
Financial impact figures are reproduced only when attributed to a named source. Entries where financial impact was not publicly disclosed are marked ‘Not disclosed.’ Modeled estimates are not included in this database; see the Hall of Shame companion article for modeled cost ranges.
This database is updated when new incidents meeting the inclusion criteria are reported by BleepingComputer, The Register, Ars Technica, Wired, Reuters, AP, or official company incident reports. The update criteria exclude: incidents without confirmed certificate root cause, incidents without named organizations, and incidents where only an anonymous source is cited.
The ‘every SSL failure since 2000’ framing requires a note: documented SSL certificate expiry incidents before 2010 are sparsely recorded in publicly accessible primary sources. The pre-2011 web operated under different HTTPS adoption rates and the culture of public post-mortems had not yet developed. This database covers verified incidents from 2011 onward. Incidents before 2011 with verified documentation will be added as they are identified. Claims of incidents before 2011 without verifiable primary sources are not included.
