The Dutch Institute for Vulnerability Disclosure, the volunteer organisation that spends its days warning others about exposed systems, has been hacked. DIVD says the intruder exploited a vulnerability in one of its systems and then left the rest of the work to an autonomous AI agent.
DIVD disclosed the breach on 24 September in a blog post with a self-aware title, It was a matter of when, not if. After almost seven years of operation, the organisation wrote, it could now call itself one of “the hackers that got hacked”. It spotted the suspicious activity itself, blocked access to its infrastructure and brought in an external incident response team for the forensics.
The same day it informed the parties directly involved and reported the incident to the Dutch data protection authority, Autoriteit Persoonsgegevens, and to the National Cyber Security Centre. It also discussed its options with the police. Until the investigation shows otherwise, DIVD is treating the incident as a worst case and assuming breach.
An Intruder That Narrated Its Own Moves
In an update on Monday, DIVD described the attack as “loud and very very messy”. The agent chose each next step itself, at speed and with sloppy logic. At one point its password spraying disrupted its own adversary-in-the-middle attack.
It also over-explained its decisions in its comments. DIVD believes the agent was poorly trained and badly configured for the job and the trail it left is enough for investigators to reconstruct the intrusion.
The way in was an ordinary vulnerability in a system DIVD has not named. It has ruled out Citrix NetScaler whose two zero-days CISA added to its Known Exploited Vulnerabilities catalogue on 27 September.
What DIVD Has Not Said Yet
The purpose of the attack is unknown and so is what, if anything, the attacker took. DIVD is withholding technical detail so that it does not disturb the investigation or expose other organisations running the same vulnerable system and says it will notify them as soon as it can. A fuller update is due on 1 October.
Treat the agentic AI attack label as DIVD’s working assessment until then. It rests on how the intruder behaved, not on a recovered tool or a named model and nothing has been published that outsiders can check. The people making the call analyse intrusions for a living which counts for a lot. It does not replace the evidence.
Spain, ENISA and Microsoft Flagged Agent-Driven Attacks in September
DIVD’s case is not isolated. In mid-September Spain’s data protection agency, AEPD, said it had received its first breach notification describing an attack carried out by an AI agent built on a known large language model. The agency has not yet verified the organisation’s account.
On 22 September ENISA published its Threat Landscape 2026 which assesses that AI will highly likely support malicious operations to a growing degree and that 2026 may see experiments with attacks that run without a human in the loop. Three days later Microsoft described agent-driven attacks by a group it tracks as Storm-3168. The group used compromised Azure service principals and targeted more than 100 storage accounts in a destructive stage that lasted seven minutes.
DIVD Spotted the Activity Itself
The most useful line in DIVD’s first statement is the least dramatic one, it noticed the suspicious activity itself. An intruder that picks its own next move at machine speed shortens the gap between foothold and damage, and a weekly log review will not close it.
Patch internet-facing systems against actively exploited flaws first. DIVD’s attacker still needed an ordinary vulnerability to get in and the agent only took over after that.
Hunt for automation inside the network, not only at the edge. Password spraying from internal hosts and bursts of commands issued faster than any person types are the patterns DIVD’s account points to.
If DIVD contacts your organisation once its investigation ends, treat the message as an incident report, not a courtesy notice.
References
- It Was a Matter of When, Not If
- Automated AI Agent Used to Breach Cybersecurity Nonprofit DIVD
- Spain’s Data Agency Gets First Report of AI-powered Data Breach
- ENISA Threat Landscape 2026
- JadePuffer Agentic AI Attacks Target Azure, Destroy Cloud Resources
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
This post is also available in:


