On 2026-09-24 the Dutch Institute for Vulnerability Disclosure (DIVD) said it had been hacked and that the attack's modus operandi indicated agentic AI. DIVD's case pages, last modified 2026-10-01, say first access was on 2026-09-21 through two previously unknown vulnerabilities in the Zammad ticketing system (CVE-2026-102489 and CVE-2026-102490) and that DIVD "got hacked through AI agents"; press reports quote DIVD as saying the two flaws let the attacker hijack sessions, run code and reach root "in seconds, due to the agentic part of this hack". DIVD's separate data overview says the attackers got in through the ticketing system its CSIRT team uses, that data was compromised and possibly exfiltrated, and that extraction was difficult for them. DIVD reported the flaws to Zammad on 2026-09-24 and advises upgrading to Zammad 7; the agentic characterization is DIVD's own assessment and its investigation is open.
It is an intrusion into a vulnerability-disclosure organization that the victim attributes to AI agents and says began with two previously unknown flaws in its ticketing software, with the victim publishing its timeline and the status of its data, though the attribution rests on DIVD's reading of the attack while forensics continue.
Key facts
As stated in the sources, with where to find them.
- DIVD says the modus operandi indicates an agentic AI powered attack, that it cannot rule anything out and handles the incident as a worst case, assuming breach until proven otherwise. Its case page states that DIVD "got hacked through AI agents" and that the investigation is ongoing.DIVD CSIRT post, 2026-09-24, paragraphs 3-4; case DIVD-2026-00014, Summary
- DIVD's timeline: first access 2026-09-21; DIVD aware on 2026-09-22, when it blocked access to all datacenter systems and started a forensic investigation with Merlon Security; vulnerabilities reported to Zammad and first public statement on 2026-09-24; limited disclosure and notification of owners of vulnerable instances from 2026-09-26; partners and affected parties told on 2026-09-30 about data that might have been breached; an overview of the data investigation published on 2026-10-01.Case DIVD-2026-00014, Timeline; case DIVD-2026-00015, Timeline
- DIVD says the attackers got in through two zero-day vulnerabilities in the Zammad ticketing system. CVE-2026-102489 is a session hijack leading to remote code execution as the zammad user in Zammad 6.3.0 to 6.5.4 (also present in 7.0.0 to 7.1.3 but not exploitable there because of environment conditions); CVE-2026-102490 lets the local zammad user escalate to root and affects all versions up to the 7.1.0 alpha. A patch is available; DIVD recommends upgrading to Zammad 7 or taking the instance offline.Case DIVD-2026-00015, Summary and header
- SecurityWeek reports both CVEs have a CVSS score of 9.4 and that the first allows unauthenticated remote code execution and session leaks. DIVD's case page, as archived, does not give a score.SecurityWeek
- BleepingComputer and SecurityWeek quote DIVD as saying the two flaws together let the attackers hijack sessions, run code remotely and escalate from the Zammad user to root "in seconds, due to the agentic part of this hack"; BleepingComputer reports that the agent left clear explanations of its decisions, which let DIVD reconstruct the incident, and that network segmentation and incident response kept the attacker from moving deeper.BleepingComputer, 2026-09-30; SecurityWeek
- BleepingComputer reports that in an update dated 2026-09-28 DIVD called the attack loud and very messy, said the agent decided each next step itself, did some pretty dumb things (including interfering with its own adversary-in-the-middle attack through password spraying), and that DIVD believes it was poorly trained and configured. DIVD's own page for that update was not found; these details are as BleepingComputer reports them.BleepingComputer, 2026-09-29
- DIVD's data overview says the attackers got in through the ticketing system its CSIRT team uses, which holds every email sent to the CSIRT mailbox and every reply, but not DIVD's initial notifications (the overview does not name the system; DIVD's case pages name Zammad as the entry point); that data was compromised and possibly exfiltrated; that DIVD email addresses were exfiltrated and volunteers' contact details possibly; that the attackers had difficulty extracting information, so only part was taken; and that anyone who corresponded with the CSIRT team should assume that content may be exposed. Accounting and bank systems are handled by an external party with no signs of compromise found, and most other categories were marked ongoing as of 2026-10-01.Overview of data investigation, Current picture and status tables
- DIVD reported the incident to the Autoriteit Persoonsgegevens and the National Cyber Security Centre, discussed options with the police, published a log-check script for indicators of compromise, and is scanning for and alerting owners of vulnerable Zammad instances.DIVD CSIRT post, 2026-09-24; case DIVD-2026-00015, What we are doing; SecurityWeek
Findings that cite this record
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
- It was a matter of when, not if...
- DIVD-2026-00014 - When, not if...
- DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DIVD-2026-00014
- Overview of data investigation
- Automated AI agent used to breach cybersecurity nonprofit DIVD
- DIVD says Zammad zero-days enabled AI-driven network breach
- Zammad Zero-Days Exploited in AI-Powered DIVD Hack