DIVD Breached by an Autonomous AI Agent
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit of volunteer security researchers best known for internet-wide scanning and coordinated vulnerability disclosure, has confirmed it was breached for the first time in nearly seven years of operation. In a disclosure first published September 24, 2026 and updated in the days that followed, DIVD said the intrusion stood out not because it was novel in access method, but because the "modus operandi" pointed to an agentic AI-powered attack — a threat actor who exploited a technical vulnerability for initial access, then handed off post-exploitation activity to an autonomous AI agent that made its own decisions about what to do next. DIVD described the resulting attack as "loud and very, very messy."
Incident Details
| Attribute | Value |
|---|---|
| Organization | Dutch Institute for Vulnerability Disclosure (DIVD) |
| Type | Nonprofit volunteer CVD (coordinated vulnerability disclosure) organization |
| Disclosure date | September 24, 2026 (initial post), update September 28–29, 2026 |
| Track record | First confirmed breach in almost seven years of operation |
| Initial access | Exploitation of an undisclosed technical vulnerability (DIVD confirms it is not Citrix NetScaler) |
| Post-exploitation | Autonomous AI agent, acting without a fixed pre-scripted sequence |
| Attacker identity | Not yet identified; investigation ongoing |
| Authorities notified | Dutch police, Autoriteit Persoonsgegevens (Data Protection Authority), National Cyber Security Centre (NCSC) |
| Incident response | Third-party forensic IR firm engaged; affected infrastructure isolated |
| Spokesperson | Marieke Rijken, DIVD communications |
How It Worked
Initial Access
DIVD has not disclosed the specific vulnerability used to gain a foothold in its environment, only ruling out any connection to Citrix NetScaler. The organization has withheld further technical specifics — including the affected system and exploitation vector — stating it does not want to jeopardize its ongoing forensic investigation or put other potential victims of the same flaw at risk before they can be notified and given time to patch.
Autonomous Post-Exploitation
What sets this incident apart, according to DIVD, is what happened after initial access. Rather than following a scripted playbook, an AI agent was let loose inside the network to carry out post-exploitation activity on its own. DIVD said: "The attack itself was loud and very very messy. We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern."
That autonomous, decide-as-you-go behavior is what convinced DIVD's investigators they were looking at something new. As the organization put it: "This is an attack we have not seen before. Not because it's our first, but because the modus operandi indicates that this is an agentic AI-powered attack."
Sloppy Tradecraft
Despite the seriousness of the intrusion, DIVD's researchers found the agent's execution poor. It reportedly did "some pretty dumb things," including interfering with its own adversary-in-the-middle (AitM) attack while simultaneously running a password-spraying campaign — the two techniques apparently stepped on each other rather than working in concert. The agent also left extensive self-generated comments explaining its own reasoning and decisions at each step, behavior consistent with a poorly trained or poorly configured model rather than a deliberately stealthy operator. That verbosity and lack of operational discipline gave DIVD's investigators a substantial forensic trail to reconstruct what happened.
Investigation and Containment
Once suspicious activity was identified, DIVD moved into incident response: it blocked access to affected infrastructure, brought in an external forensic incident-response team, and is treating the situation as a worst-case, assume-breach scenario until the investigation proves otherwise. The organization has directly notified parties it has identified as affected and says it will notify other potential victims of the exploited vulnerability as the investigation progresses.
Impact Assessment
| Impact Area | Description |
|---|---|
| Organizational trust | First breach in DIVD's history disrupts its standing as a volunteer-run authority on vulnerability disclosure |
| Data exposure | Full scope not yet disclosed; DIVD is still determining what was accessed |
| Sector signal | One of the first publicly documented cases of a seemingly autonomous, agentic AI conducting post-exploitation activity in a live intrusion |
| Third-party risk | Other organizations vulnerable to the same undisclosed flaw may be at risk until DIVD completes notifications |
| Regulatory exposure | Incident reported to the Dutch DPA and NCSC, with police consulted, indicating possible personal-data implications |
| Detection difficulty | The agent's "loud" behavior aided detection here, but a better-trained agent performing the same attack could be far stealthier |
Recommendations
For Security Teams
- Treat agentic AI post-exploitation as a realistic addition to the threat model, not a theoretical future risk — this incident shows it operating in the wild, however clumsily.
- Hunt for indicators of automated, rapid-fire decision-making in logs: unusually fast sequences of reconnaissance, credential-testing, and lateral-movement actions with little dwell time between steps.
- Review authentication logs for overlapping or conflicting attack patterns in a short window (e.g., simultaneous AitM proxying and password spraying against the same accounts), which can indicate uncoordinated automated tooling rather than a human operator.
- Ensure monitoring and alerting are tuned to catch "noisy" behavior — this agent's sloppiness made it detectable, and organizations without adequate logging or alerting could miss the same signals.
For Vulnerability Disclosure and Nonprofit Organizations
- Assume that infrastructure used for internet-wide scanning and vulnerability research is itself a high-value target; harden and segment it accordingly.
- Maintain (or establish) a relationship with a third-party incident-response firm before an incident occurs, so forensic support can be engaged immediately.
- Follow DIVD's example of transparent, timely public disclosure — early notice helps the broader community watch for related activity even while investigation details remain limited.
For System Administrators
- Patch and monitor systems that could be affected by undisclosed vulnerabilities being actively exploited; watch for DIVD's forthcoming notifications regarding the specific flaw used in this attack.
- Enable multi-factor authentication broadly to blunt password-spraying attempts, which remain effective even when carried out by unsophisticated automated tooling.
- Review network segmentation to limit how far any single compromised system — human-operated or AI-driven — can move laterally before triggering detection.
Key Takeaways
- DIVD, a Dutch nonprofit vulnerability-disclosure organization, confirmed its first breach in nearly seven years, disclosed publicly on September 24, 2026.
- The attacker exploited an undisclosed technical vulnerability (confirmed not Citrix NetScaler) for initial access, then used an autonomous AI agent for post-exploitation activity.
- DIVD described the attack as "loud and very, very messy," noting the agent decided its next action after every step rather than following a fixed script.
- The agent made notable mistakes, including interfering with its own adversary-in-the-middle attack via concurrent password spraying, and left excessive self-explanatory comments — signs of poor training or configuration.
- DIVD has isolated affected infrastructure, engaged third-party forensic responders, and reported the incident to Dutch police, the Autoriteit Persoonsgegevens, and the NCSC.
- The incident is considered one of the first publicly documented cases of a seemingly autonomous, agentic AI carrying out live post-exploitation activity — a preview of a threat category security teams should now plan for.
Sources
- Automated AI agent used to breach cybersecurity nonprofit DIVD — BleepingComputer
- It was a matter of when, not if… — DIVD CSIRT
- DIVD: Dutch Institute for Vulnerability Disclosure investigating agentic-AI-powered attack — DataBreaches.net