DIVD says AI agent carried out cyberattack through software
The Dutch Institute for Vulnerability Disclosure reported an autonomous AI agent conducting post-exploitation activities within its network following a.
- Reported date
- Sep 29, 2026
- Target
- Dutch Institute for Vulnerability Disclosure
- Agent type
- Other AI agent
- Agent role
- Used by the attacker
The exact incident date was not established. This entry is dated by its source report.
The Dutch Institute for Vulnerability Disclosure (DIVD) recently disclosed that an autonomous AI agent was utilized to conduct post-exploitation activities within its infrastructure following an initial breach. The organization, which typically identifies and reports vulnerabilities to other entities, is currently investigating the extent of the compromise after detecting the unusual automated activity.
What happened
Following an initial intrusion through an undisclosed technical vulnerability—which DIVD confirmed was not related to Citrix NetScaler—the attackers deployed an autonomous AI agent to navigate the network. DIVD characterized the incident as an agentic AI-powered attack because the system appeared to determine its subsequent actions dynamically rather than following a pre-programmed sequence.
Researchers described the agent’s behavior as "noisy and messy," noting that it moved quickly but exhibited poor logic. The agent made several operational errors, such as interfering with its own adversary-in-the-middle operation by simultaneously performing password spraying. Furthermore, the system left behind machine-generated comments explaining its actions, which has provided investigators with a significant forensic trail to reconstruct the attack's decision-making process.
DIVD has not yet identified the threat actor or confirmed whether any data was stolen or altered. Upon detecting the activity, the organization isolated parts of its infrastructure and engaged an external incident response team. The incident has been reported to the Dutch Data Protection Authority, the National Cyber Security Centre, and the police. DIVD is currently withholding specific technical details regarding the vulnerable system to prevent potential exploitation of other organizations that may share the same technology. The investigation remains ongoing, and the organization plans to notify other potential victims once it can do so safely.
Evidence in the reporting
- Incident evidence
- attackers had gained access to its systems
- Agent involvement
- AI agent operated autonomously inside DIVD network