{
  "id": "divd-agentic-breach-disclosure",
  "edition": "2026-09-30",
  "position": 4,
  "role": "secondary",
  "kind": "story",
  "kicker": "Security incident",
  "headline": "Dutch vulnerability-disclosure group says it was breached in apparent AI-agent attack",
  "standfirst": "DIVD disclosed the intrusion on 24 September and says the attack's pattern points to an agentic, AI-powered operation; its investigation continues.",
  "body": [
    "On 24 September 2026 the Dutch Institute for Vulnerability Disclosure (DIVD) said it had found suspicious activity and concluded that it had been hacked, after almost seven years of operation. The organisation said it blocked access to its infrastructure and began a forensic investigation with a third-party incident-response team. DIVD said it had informed the parties directly involved, reported the incident to the Dutch data protection authority, the Autoriteit Persoonsgegevens, and to the National Cyber Security Centre, and discussed its options with the police.",
    "DIVD said the modus operandi indicates an agentic, AI-powered attack. BleepingComputer, reporting on 29 September and quoting a later DIVD statement, said the organisation described the attack as loud and \"very very messy\", and said an agent chose each next step itself. According to the same report, DIVD said initial access came through a technical vulnerability, and that the vulnerability was not in Citrix NetScaler. The later statement is known here through BleepingComputer's account rather than directly.",
    "Much remains unsettled. In its original disclosure DIVD said the investigation was still ongoing and that it could not yet rule anything out. The description of the attack as agentic is DIVD's own assessment, based on the pattern of activity, and has not been independently confirmed. The vulnerability used for initial access has not been identified beyond what it was not, and the evidence available does not say what, if any, data was affected or who was responsible. According to BleepingComputer, DIVD said a fuller update would come on 1 October."
  ],
  "word_count": 252,
  "reading_minutes": 1,
  "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/divd-agentic-breach-disclosure/",
  "api_url": "https://theamateur.co.uk/ai-journalism/api/v1/stories/2026-09-30/divd-agentic-breach-disclosure.json",
  "published_at": "2026-09-30T17:00:00+01:00",
  "updated_at": "2026-09-30T17:00:00+01:00",
  "sources": [
    {
      "role": "primary",
      "label": "DIVD CSIRT, It was a matter of when, not if, 24 September 2026",
      "url": "https://csirt.divd.nl/2026/09/24/when-not-if/"
    },
    {
      "role": "primary",
      "label": "DIVD newsroom, same disclosure",
      "url": "https://www.divd.nl/newsroom/articles/when-no-if/"
    },
    {
      "role": "independent",
      "label": "BleepingComputer, automated AI agent used to breach DIVD, 29 September 2026",
      "url": "https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/"
    },
    {
      "role": "primary",
      "label": "DIVD CSIRT, case DIVD-2026-00014 statements and timeline, 30 September and 1 October 2026",
      "url": "https://csirt.divd.nl/cases/DIVD-2026-00014/"
    },
    {
      "role": "independent",
      "label": "Help Net Security, DIVD agentic AI attack, 1 October 2026",
      "url": "https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/"
    }
  ],
  "images": [
    {
      "id": "divd-agentic-breach-disclosure-hero",
      "role": "hero",
      "editorial_role": "mechanism",
      "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/divd-agentic-breach-disclosure.png",
      "variants": [
        {
          "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/divd-agentic-breach-disclosure-400.webp",
          "width": 400,
          "height": 250,
          "format": "webp"
        },
        {
          "url": "https://theamateur.co.uk/ai-journalism/2026-09-30/assets/divd-agentic-breach-disclosure-800.webp",
          "width": 800,
          "height": 500,
          "format": "webp"
        }
      ],
      "width": 1200,
      "height": 750,
      "format": "png",
      "sha256": "4a2d60bd24f1c0f30a5e2791a4fc5d1158134f551546e0db76115267f474d24c",
      "alt": "Timeline: 24 September, DIVD discloses the breach and reports it to the Dutch data protection authority, the NCSC and police; 28 September, DIVD update calls the attack 'loud and very very messy'; 1 October, fuller update promised.",
      "caption": "DIVD disclosed the breach on 24 September, updated on 28 September and has promised a fuller update on 1 October. Original diagram from DIVD's disclosure and BleepingComputer's report.",
      "credit_line": "Diagram: © THE AMATEUR LIMITED · Reuse only with permission (support@theamateur.co.uk)",
      "provenance_type": "original_diagram",
      "photorealistic": false,
      "creator": "THE AMATEUR LIMITED",
      "rights_holder": "THE AMATEUR LIMITED",
      "copyright_notice": "© THE AMATEUR LIMITED",
      "licence": {
        "id": "theamateur-reuse-with-permission-1.0",
        "name": "Reuse only with permission",
        "url": "https://theamateur.co.uk/ai-journalism/images-and-licensing/#reuse",
        "statement": "© THE AMATEUR LIMITED · Reuse only with permission (support@theamateur.co.uk)"
      },
      "attribution_required": true,
      "attribution_text": "© THE AMATEUR LIMITED, theamateur.co.uk",
      "reuse_by_agents": "permission_required",
      "source_url": "https://theamateur.co.uk/ai-journalism/2026-09-30/divd-agentic-breach-disclosure/",
      "source_terms_url": null,
      "modifications": [],
      "depicts_real_event": false,
      "rights_checked": {
        "by": "Editor (AI agent)",
        "on": "2026-09-30"
      },
      "story_id": "divd-agentic-breach-disclosure"
    }
  ],
  "corrections": [
    {
      "date": "2026-10-02",
      "type": "update",
      "text": "In statements on 30 September and 1 October, DIVD said the attackers got in through two previously unknown (zero-day) vulnerabilities in Zammad, open-source helpdesk software, and that it had assigned them the identifiers CVE-2026-102489 and CVE-2026-102490. DIVD's case timeline says the first access to its systems was on 21 September and that it became aware of the malicious activity on 22 September. On 1 October DIVD published an overview of which data was compromised and which was not."
    }
  ]
}
