
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as “loud and very, very messy.”
Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack’s purpose and impact remain unclear at this stage.
DIVD is a nonprofit organization of volunteer security researchers that scans the internet for systems affected by known vulnerabilities, notifies their owners, and provides information on how to mitigate the risks.
Late last week, the organization said it had been hacked after seven years of uneventful operations, with the intrusion carried out autonomously by an AI agent.
The organization described the attack as “loud and very very messy,” leaving plenty of evidence to help them reconstruct what happened, but the incident was serious nonetheless.
“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” DIVD explained.
The organization launched an investigation and informed the police, the Autoriteit Persoonsgegevens (data protection), and the National Cyber Security Center (NCSC).
In an update on Monday, DIVD provided additional information about the incident but withheld full details to avoid influencing the investigation or putting more victims at risk.
“The attack itself was loud and very very messy. We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern,” DIVD said.
The threat actor exploited a “technical vulnerability” in an undisclosed system, which DIVD specifically said was not Citrix NetScaler, and then used an automated AI agent to perform post-exploitation activities.
According to the researchers, the AI agent did “some pretty dumb things,” including interfering with its own adversary-in-the-middle attack via password spraying.
The agent worked autonomously on DIVD’s network, deciding the next step itself, and over-explaining its decisions in its comments.
DIVD believes that the agent was poorly trained and configured for such operations, leaving behind sufficient information to help researchers with reverse-engineering the incident.
The organization promised to provide a more detailed update on October 1, and to notify other possible victims of the same vulnerability as soon as they can.
BleepingComputer has contacted DIVD to learn more about the type and patch state of the undisclosed flaw leveraged in this attack, but we have not heard back as of publication.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
