2026 DIVD — agentic AI-powered intrusion; AP/NCSC notified; assume-breach posture
Data compromised
Scope unpublished. DIVD states it cannot rule anything out and is treating the incident as worst-case assume-breach until proven otherwise. Directly involved parties informed; reported to Autoriteit Persoonsgegevens and Dutch NCSC; options discussed with police. Individual census unpublished.
Technical writeup
Verified DIVD CSIRT notice — September 24, 2026 (“It was a matter of when, not if…”). Dutch Institute for Vulnerability Disclosure detected suspicious activity, concluded it had been compromised, blocked infrastructure access, and engaged a third-party IR team. DIVD describes the modus operandi as an agentic AI-powered attack not previously seen in its experience; investigation ongoing; worst-case assume-breach posture. Directly involved parties informed; incident reported to Autoriteit Persoonsgegevens and the National Cyber Security Centre; discussed with police. Next public update scheduled Monday September 28 (or sooner). Spokesperson Marieke Rijken ([email protected]). Headcount and data inventory unpublished — recordsAffected 0; companyConfirmed true.
Root cause
Suspicious activity investigated as agentic AI-powered attack (DIVD CSIRT public notice Sep 24, 2026); forensics ongoing