Opens in a new tab

Dutch cybersecurity nonprofit DIVD breached by an autonomous AI agent

  • Home
  • Blog
  • Dutch cybersecurity nonprofit DIVD breached by an autonomous AI agent
Robotic arm breaching a server rack during a DIVD breach AI cyberattack

DIVD, the Dutch Institute for Vulnerability Disclosure, has disclosed that its network was breached by an autonomous AI agent that carried out post-exploitation work without human direction, a first-of-its-kind incident the nonprofit described as “loud and very, very messy.” The attacker first exploited an undisclosed technical vulnerability, then handed control to an AI agent that decided each next step on its own.

What DIVD reported

DIVD is a nonprofit of volunteer security researchers that scans the internet for systems affected by known vulnerabilities, notifies their owners, and shares mitigation guidance. After seven years of uneventful operations, the organization said late last week that it had been hacked and notified Dutch police, the Autoriteit Persoonsgegevens (the national data protection authority), and the National Cyber Security Center (NCSC).

In a Monday update, DIVD added detail without releasing full technical specifics, to avoid tipping off the attacker and putting more victims at risk. The nonprofit stated that the AI agent worked automated, choosing the next action itself at high speed, and that the agent’s behavior was sloppy enough to leave abundant evidence behind.

How the agent operated

According to DIVD’s account, the threat actor exploited a vulnerability in an undisclosed system that DIVD specifically said was not Citrix NetScaler, then deployed an AI agent for post-exploitation activity inside the network. DIVD observed the agent making its own decisions step by step, and described the result as “some pretty dumb things,” including interfering with its own adversary-in-the-middle attack during password spraying and over-explaining its reasoning in comments left behind in the environment.

DIVD’s assessment is that the AI agent was poorly trained and configured for offensive operations, which is what made the intrusion reconstructable. The nonprofit plans a more detailed update on October 1 and has said it will notify any other possible victims of the same vulnerability once it can.

Why an agentic AI attack is different

An agentic AI-powered attack is not defined by the initial intrusion but by what happens after access is gained. A traditional post-exploitation phase follows a human operator’s playbook, with each command reviewed and adjusted. In this case, the agent selected its own next move at machine speed, which is what DIVD meant when it called the modus operandi something it had not seen before, not because it was the first intrusion on the organization, but because the follow-on behavior was generated by one.

The practical consequence for defenders is that indicators of compromise become harder to predict in advance, because the sequence of actions is no longer bound to a fixed toolchain written by a human. The mitigating factor in this specific incident was poor configuration: the agent left enough commentary and noise for the victim to piece the chain back together, which is the opposite of what a careful operator would produce.

What is still unknown

DIVD has not disclosed the specific vulnerability that was exploited, its patch status, or the identity of the threat actor. The purpose of the intrusion and its full impact also remain under investigation. A more detailed technical write-up has been promised for October 1.

What defenders should track

Three signals from this incident are worth watching across other networks.

  • Speed of post-exploitation actions. A burst of activity from a freshly authenticated source that moves through enumeration, credential reuse, and lateral steps faster than a human could type is the operational fingerprint DIVD described.
  • Self-narrating artifacts. Agents that explain their reasoning in logs, scripts, comments, or chat-style output leave a trail a careful human operator would not. Searching for verbose, instructional text in unexpected places can surface agent-driven activity.
  • AI-system patch state. The initial foothold came from a known vulnerability class, not from the AI layer. Standard patching and exposure management remain the front line, and the agent only amplified what an unpatched system allowed in.

FAQ

What happened to DIVD?

DIVD disclosed that its network was breached after seven years of uneventful operations. An attacker exploited an undisclosed vulnerability, which DIVD said was not Citrix NetScaler, then used an autonomous AI agent to carry out post-exploitation activity on its own.

What did the AI agent actually do during the attack?

According to DIVD, the agent decided each next step itself at machine speed. It performed password spraying as part of an adversary-in-the-middle approach, interfered with its own attack in the process, and over-explained its decisions in comments inside the environment. DIVD described the agent as poorly trained and configured, which made the intrusion easy to reconstruct.

Why is this considered an agentic AI attack?

DIVD labeled the incident agentic AI-powered because the post-exploitation phase was driven by an AI system choosing its own next action without a human operator directing each step, rather than because the initial vulnerability exploitation involved AI.


This article summarizes reporting from bleepingcomputer.com.

← All Articles