The fake certificates could in theory be used to monitor users’ communications with those sites without them noticing, but only by an organization that also has the ability to reroute Internet traffic to servers they control — most likely a government.

A handful of Iranian users of Google’s popular e-mail service are known to have been affected.

The Dutch government said Monday Internet browser makers are now rejecting all security certificates issued by the hacked firm, DigiNotar.