It's actually much worse than that. Institutions were rarely able to actually detect said compromise, leaving attackers with certs that were indistinguishable from the real thing and valid for a long period of time. Even when institutions could detect the compromise and could quickly rotate certs, getting users to not still trust the old ones could be a non-trivial challenge.