Rouge trader using one of your cert is clearly not a real company who are scamming vulnerable people for thousands. Given they are not a real company and abusing people, is this a violation of your issuance policy, and can it be revolked?

Your question is addressed in the FAQ.


As an aside if you are technically minded and you do come across a website which is maliciously collecting personal information (for instance) you can show them some christmas spirit by helpfully scripting random submissions to their web form. The more convincing the data the better, as this obfuscates data from real people who are also helpfully submitting information. You would ideally host this script on a temporary vm such as a small AWS Lightsail instance. After several million iterations their server (or their inbox) will likely run out of disk space.


