← DIVD (Dutch Institute for Vulnerability Disclosure)

2026 DIVD — agentic AI-powered intrusion; AP/NCSC notified; assume-breach posture

2026 Unknown records affected Share on X

Data compromised

Scope unpublished. DIVD states it cannot rule anything out and is treating the incident as worst-case assume-breach until proven otherwise. Directly involved parties informed; reported to Autoriteit Persoonsgegevens and Dutch NCSC; options discussed with police. Individual census unpublished.

Technical writeup

Verified DIVD CSIRT notice — September 24, 2026 (“It was a matter of when, not if…”). Dutch Institute for Vulnerability Disclosure detected suspicious activity, concluded it had been compromised, blocked infrastructure access, and engaged a third-party IR team. DIVD describes the modus operandi as an agentic AI-powered attack not previously seen in its experience; investigation ongoing; worst-case assume-breach posture. Directly involved parties informed; incident reported to Autoriteit Persoonsgegevens and the National Cyber Security Centre; discussed with police. Next public update scheduled Monday September 28 (or sooner). Spokesperson Marieke Rijken ([email protected]). Headcount and data inventory unpublished — recordsAffected 0; companyConfirmed true.

Root cause

Suspicious activity investigated as agentic AI-powered attack (DIVD CSIRT public notice Sep 24, 2026); forensics ongoing

References