This would actually be a problem.... if the private key was good for anything. Certigna's response says it is not: "Certigna has issued a response claiming that the file represented a 'test' certificate that had long since expired. "The private key available on the server corresponds to a test certificate used on our website certigna.fr," the company claimed. "It is impossible to generate new valid user certificates…
Just some sensationalist reporting without proper fact-checking, then. Again.
"They only stole junk from my house. So Your stuff is safe, somehow"
Anyway, they Did fact-check - and the company didn't respond. So they reported what appeared to be a significant breach. Then, when the company responded, they reported that too. Which has a name, which is "Responsible Journalism"