The Dutch Institute for Vulnerability Disclosure suffered a cyberattack carried out autonomously by an artificial intelligence agent. DIVD described the incident as loud and very, very messy. The nonprofit organization of volunteer security researchers stated that it has operated for seven years without incident until this intrusion occurred late last week.
Evidence uncovered during the ongoing investigation shows the attacker exploited a technical vulnerability in an undisclosed system. DIVD explicitly clarified that the exploited flaw was not Citrix NetScaler. The threat actor used an automated AI agent to execute post-exploitation tasks across the internal network.
The agent operated with sloppy logic
DIVD researchers observed the agent working autonomously at high speed using sloppy logic and pattern matching. The AI agent performed actions such as interfering with its own adversary-in-the-middle attack using password spraying. The automated system also over-explained its decisions in comments left behind on the network.
DIVD believes the agent was poorly trained and configured for these operations. This poor configuration left behind sufficient information to help investigators reverse-engineer the incident. The exact purpose and impact of the attack remain unclear at this stage of the investigation.
DIVD reported the breach to the police
The organization launched a formal investigation and reported the breach to the police. DIVD also notified the Autoriteit Persoonsgegevens data protection authority and the National Cyber Security Center. The nonprofit promised to provide a more detailed public update on October 1.



