A vulnerability-disclosure team was hacked: DIVD suspects an agentic AI-powered attack
DIVD isolated its infrastructure and began forensics. We separate confirmed facts from an early AI hypothesis and explain the response lessons.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 28 September 2026
- READING TIME
- 10 min read
- TOPIC
- AI Security
The Dutch Institute for Vulnerability Disclosure (DIVD), whose volunteers find exposed systems and notify their owners, has disclosed a compromise of its own infrastructure. The organisation blocked access, began a forensic investigation with an external incident-response team and adopted the cautious working assumption that a breach had occurred until evidence showed otherwise.
The statement attracting the most attention is DIVD’s view that the modus operandi indicates an agentic AI-powered attack. This is an early assessment, not a published technical report proving the use of a particular model or autonomous system. Both points matter: the observation of an experienced team should not be ignored, but a hypothesis should not become a certainty.
What has been confirmed
DIVD detected suspicious activity and concluded after investigation that it had been hacked. It blocked access to its infrastructure and began forensics with support from an independent incident-response team.
The organisation notified directly involved parties, reported the incident to the Dutch data-protection authority and National Cyber Security Centre, and discussed its options with police. It listed isolation and infrastructure security, forensic work and support for volunteers as immediate priorities.
The initial notice does not describe the entry path, affected systems, available data, attacker dwell time or confirmed exfiltration. It does not identify an actor or a specific AI tool.
“Indicates agentic AI” does not mean “AI has been proven”
An attack may look automated for many reasons: rapid sequences, parallel attempts, adaptation to system responses, unusual commands or orchestration of several tools. These characteristics can support an agent hypothesis but are not sufficient to attribute the technology by themselves.
A stronger conclusion would require evidence of an observe–decide–act loop, characteristic tool errors or artefacts, timing correlation, operator infrastructure, captured prompts or other indicators. Even then, the review must distinguish an autonomous agent from a script, an orchestrator and a human making intensive use of an AI assistant.
The distinction matters to the business. Response should focus first on access obtained, data affected and attacker persistence, not the most compelling label. During the first hours, “was it AI?” is usually less urgent than “what can the attacker do now?”
Why “assume breach” can be a sensible working model
During an active investigation, incomplete evidence should not create false reassurance when there are credible access indicators. Assuming compromise allows a team to isolate systems, preserve logs, rotate keys and notify people who can reduce harm.
This does not mean publicly claiming that every dataset was stolen. An internal working hypothesis can be conservative while external communication remains precise about what was detected, which actions were taken and what remains unresolved.
That approach is particularly important for an organisation holding information about vulnerabilities in other entities. Data value depends not only on confidentiality but also on time: an issue that an owner has not yet fixed could be exploited quickly.
Preparing for a faster and more adaptive attacker
Whether agentic AI is ultimately confirmed in this case or not, teams should expect automation to shorten the time between access and the next action. Manual approval and communication cannot remain the only mechanisms capable of stopping an attack.
An organisation needs:
- central logs that remain available after a source system is isolated;
- short-lived credentials and rapid key revocation;
- segmentation that restricts movement between services;
- alerts for action sequences, not only individual indicators;
- a prepared isolation list and named decision owners;
- a trusted communication channel outside the potentially compromised environment;
- a current inventory of data, partners and people who may require notification.
Speed should not remove control over consequences. Automated containment needs scope, rollback conditions and oversight so that the response does not disrupt services more severely than the attacker.
Transparency does not require publishing every detail
DIVD chose to confirm the compromise early and state that the investigation continued. Such communication can help partners prepare, but it requires disciplined language. Hypotheses should remain labelled as hypotheses, and a promised update date cannot substitute for useful content.
An organisation should not publish information that helps an attacker retain access or destroy evidence. It can still provide service status, types of protective action, potentially affected groups, a contact channel and the date of the update.
DIVD’s reference to looking after volunteers is also important. An incident is not merely technical. Sustained work under pressure increases error risk, making shift planning, rest and decision support part of operational security.
What to preserve when AI use is suspected
If a team suspects an agentic system, it should retain raw events, timestamps, complete commands, service responses, unusual error variants and the sequence of tool use. A later assessment without original data can easily turn into a story based on impressions.
The final report should separate observation from interpretation and assign confidence. “Actions occurred seconds apart across several services” is an observation. “The attacker used an autonomous agent” is a conclusion requiring additional support.
Source facts and Breachroad’s conclusions
DIVD CSIRT confirms the compromise, infrastructure isolation, external forensic support, notification of relevant parties and authorities, and its own assessment that the modus operandi indicates an agentic AI-powered attack. The notice does not provide technical proof of that hypothesis or the incident’s full scope.
The evidentiary standard for AI attribution, response priorities, control list and communication guidance are Breachroad’s conclusions. See our analysis of offensive AI use in cybercrime and incident-response planning. Organisations deploying agents can define safer operating boundaries through a secure AI implementation review.


