AI-Driven Cyberattack Hits Dutch Vulnerability Disclosure Institute
The **Dutch Institute for Vulnerability Disclosure (DIVD)**, a prominent cybersecurity nonprofit, has reported an unprecedented cyberattack orchestrated by an autonomous AI agent. Described as 'loud and very, very messy,' the incident marks a significant shift in the threat landscape, highlighting the emerging risks posed by AI in offensive operations.

The **Dutch Institute for Vulnerability Disclosure (DIVD)**, a volunteer-driven nonprofit dedicated to identifying and mitigating internet vulnerabilities, recently disclosed an unusual cyberattack. The organization, which had operated for seven years without incident, confirmed that the breach was carried out by an autonomous AI agent.
### An Unprecedented Modus Operandi
**DIVD** described the attack as unique, stating, "This is an attack we have not seen before. Not because itβs our first, but because the modus operandi indicates that this is an agentic AI-powered attack." The nature of the attack, characterized by its 'loud and very, very messy' execution, left ample evidence for investigators.
### The Attack Vector and AI's Role
Investigators believe the attacker exploited a "technical vulnerability" in an undisclosed system, which **DIVD** explicitly stated was not **Citrix NetScaler**. Following the initial breach, an automated AI agent took over post-exploitation activities. **DIVD** noted the agent's autonomous decision-making process, observing it would "decide the next step itself, at the speed of light and sloppy logic or pattern."
Intriguingly, the AI agent's actions were sometimes counterproductive, including interfering with its own adversary-in-the-middle attack through password spraying. Researchers suggest the agent was "poorly trained and configured" for such operations, leaving behind valuable information for reverse-engineering the incident.
### Ongoing Investigation and Future Disclosures
**DIVD** has initiated a thorough investigation, notifying the police, the **Autoriteit Persoonsgegevens** (Dutch data protection authority), and the **National Cyber Security Center (NCSC)**. While full details are being withheld to avoid compromising the investigation or endangering other potential victims, **DIVD** has committed to providing a more comprehensive update on October 1.
The organization also plans to notify other possible victims of the exploited vulnerability once they are able to do so. This incident serves as a stark reminder of the evolving challenges in cybersecurity, as threat actors begin to leverage advanced AI capabilities.