DIVD got breached and says an agentic AI attack did it
The Dutch vulnerability disclosure institute disclosed a breach it attributes to an agentic AI powered attack. Their response is the template worth copying.
The Dutch Institute for Vulnerability Disclosure — the volunteer CSIRT whose entire job is telling other organizations they have been exposed — published a post on September 24 saying it had been breached. DIVD calls the method "an agentic AI powered attack," a modus operandi it had not seen before. If the people who run coordinated vulnerability disclosure for a living can get hit by this, your assumptions about who is a target need updating today.
What actually happened
From DIVD's own disclosure, titled "When, not if":
- DIVD detected suspicious activity, investigated, and confirmed a compromise after nearly seven years of operation.
- Access to its infrastructure was blocked immediately and a third-party incident response team was engaged for forensics.
- The scope of affected data is not yet determined. DIVD says it will "handle this situation as a worst-case-scenario and assume breach until proven otherwise."
- It notified directly involved parties, reported to the Autoriteit Persoonsgegevens (the Dutch data protection authority) and the National Cyber Security Centre, and discussed options with police.
- The next public update is promised for Monday, September 28, or sooner.
What we are deliberately not saying: how the attack worked. DIVD has published an attribution of method, not a technical writeup, and forensics are ongoing. "Agentic AI powered" is their characterization from an investigation that is four days old. Treat it as a signal about direction, not a finished case file — and wait for the 28th before you build a detection rule on it.
Why agentic AI attacks matter for your business
The economics of being a small target just inverted. Manual attacks pick targets worth the analyst's hour. Agentic tooling does not have an hourly rate. When reconnaissance, credential stuffing, and lateral movement run as an unattended loop, a twelve-person company with a stale admin account is no longer beneath notice — it is just another row in a queue. We made this argument about dead permissions and help desk vishing. This is the same trend with a name attached.
"Assume breach until proven otherwise" is the correct default, and almost nobody's plan says it. Most small-business incident plans — when they exist — start from "determine whether we were breached." That ordering costs you days. Flip it: revoke and rotate first, scope second. It is cheaper to re-issue credentials you did not need to re-issue than to leave an active session alive for a week while you build certainty.
Write the disclosure before you need it. DIVD went public with an incomplete picture, named the regulators it contacted, and committed to a dated follow-up. That is not bravery, it is preparation — a template, a notification list, and a decision already made about who gets told and when. Draft yours on a quiet Tuesday. You will not write it well at 2 a.m. with legal on the phone.
Key takeaways
- DIVD, a Dutch coordinated vulnerability disclosure CSIRT, disclosed a breach on September 24
- It attributes the intrusion to "an agentic AI powered attack" — a method new to the organization
- Data impact is undetermined; DIVD is assuming full breach until forensics prove otherwise
- It notified affected parties, the Autoriteit Persoonsgegevens, the NCSC, and police, with a next update due September 28
- Automated attack tooling removes the cost floor that used to keep small companies off target lists
- Flip your incident order: revoke and rotate first, scope second — and draft the disclosure template now
Most small businesses discover their access map during the incident. We audit who and what can reach your systems — service accounts, stale API keys, third-party integrations, agent credentials — and build the revoke-first runbook before you need it. See how we harden small stacks, or get a read on your exposure.
Sources: DIVD CSIRT.
- #security
- #incident-response
- #agentic-ai
- #breach-disclosure
- #ai-attacks
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
WSO2 CVE-2026-5430: a forged token walks your gateway
CISA added WSO2 CVE-2026-5430 to KEV on September 24 with a three-day federal deadline. WSO2 published the fix in May. Check your API Manager update level.
Read itZyxel GS1900 flaw: 996 switches robbed, fix shipped in June
CVE-2026-7273 let a LAN attacker run commands on Zyxel GS1900 switches. 996 were looted across 48 countries — three months after Zyxel published the firmware.
Read it