A Japanese certificate authority force revoked security certificates for an estimated 15,000–20,000 Russian domains starting June 13, after new rules made sanctions screening mandatory for the companies that issue browser padlocks.
On June 13, 2026, GlobalSign, the Japanese-owned certificate authority, force-revoked the TLS certificates it had previously issued to an estimated 15,000–20,000 Russian domains. A second wave hit 310 more across 44 named companies, including Rosneft, Gazprombank, Alrosa, and Positive Technologies. The trigger was a rule change three weeks earlier: starting May 4, 2026, the CA/Browser Forum, the standards body whose rules govern the digital padlocks every browser trusts, made OFAC, U.S. Bureau of Industry and Security, and European Union sanctions screening mandatory for the companies that issue those certificates.
That rule effectively turned TLS issuance into a sanctions-enforcement surface, and the browser padlock into a geopolitical instrument.
TLS certificates are the small files a browser checks before opening any HTTPS site. If a certificate is missing, expired, or issued by an authority the browser does not recognize, Chrome, Firefox, and Safari replace the padlock with a red "Not Secure" warning or refuse to load the page at all. Mainstream browsers maintain a built-in "trust store" of certificate authorities they will accept. Companies outside that list are not loaded by default, no matter how technically valid their certificate is.
Independent Russian outlet Mediazona reported on August 3, 2026 that seven major Russian banks now serve certificates from a Russian state root that mainstream browsers do not trust, forcing users to manually install them. The same reporting found that Russian state services, including the Federal Tax Service, are increasingly failing to load in mainstream browsers at all. Ukraine's Foreign Intelligence Service, an adversary of the Russian state, publicly characterized the resulting environment on August 12, 2026 as leaving Russian internal systems, messengers, email, and banking APIs "ideal targets for hacker attacks." That risk assessment comes from a single interested party with a motive to publicize Russian vulnerability. No specific breach has been reported in the cited material.
Per the CA/Browser Forum rules effective May 4, 2026, every certificate authority that wants to remain in browser trust stores must now run the same sanctions screening a bank would run before opening an account. The Russian state, a sanctioned economy, is now structurally cut off from the global trust infrastructure. Ukraine's intelligence estimate that roughly 90% of the Russian certificate market still depends on foreign issuers is just that, an estimate, but it gives a sense of scale. The remaining 10% is mostly the state root, the option that does not work for users without manual intervention.
The Russian government's response, a state-run certificate authority whose root is not in any mainstream browser's trust store, shifts the burden onto ordinary users. It also surfaces the legitimate critique: this is a blunt tool that punishes Russian users, including ordinary users of state services like the tax authority, alongside the sanctioned entities the policy is meant to target. It sets a precedent that turns browsers and certificate authorities into de facto geopolitical actors, whether they want to be or not. Tomorrow's rules might be written for a different target, but the technical mechanism now exists: any country whose policy goals align with the standards body's membership can route enforcement through the browser padlock.
In Moscow today, a user trying to file with the Federal Tax Service may see a red "Not Secure" warning, or nothing at all. The padlock, designed in the 1990s to verify identity, is now doing the work the sanctions list used to do.