Back
AI agents hacked the hackers at DIVD, stealing volunteer email addresses
SiTech AI Team3 min read

AI agents hacked the hackers at DIVD, stealing volunteer email addresses

The Dutch Institute for Vulnerability Disclosure says attackers chained two Zammad zero-days to steal its volunteers' data, including DIVD email addresses. The nonprofit says the modus operandi points to an agentic AI-powered attack.

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that hunts software flaws, was hacked on September 21 through two previously unknown vulnerabilities in its Zammad helpdesk platform. Attackers stole data belonging to the organization's volunteer security researchers, including DIVD email addresses. DIVD says the modus operandi points to an agentic AI-powered attack.

What happened

The chained exploits moved from session hijacking to root access in seconds. CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions; CVE-2026-102490 lets a local user escalate privileges to root. DIVD is a CVE Numbering Authority and assigned both identifiers; it scored the bugs 9.4 under CVSS 4.0 when assessed as a chain.

Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489. The flaw also exists in versions 7.0.0-7.1.3, but is not exploitable there "due to environment conditions", DIVD's advisory says. CVE-2026-102490 affects all Zammad versions. DIVD advises all Zammad users to upgrade to version 7 or take it offline.

Timeline and response

The attack happened on September 21; DIVD discovered it the next day, blocked access to all of its data center systems and formed an incident response team with Merlon Security. On September 24 it reported the flaw to the Zammad vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre, and discussed next steps with police. It published its first public disclosure on LinkedIn the same day, noting it took "almost seven years" before it could say "we're the hackers that got hacked".

Agentic AI, by the modus operandi

"This is an attack we have not seen before," DIVD wrote. "Not because it's our first, but because the modus operandi indicates that this is an agentic AI powered attack." The nonprofit described the attack as "loud and very very messy" and said it could see the agent deciding each next step by itself, at the speed of light and with sloppy logic or pattern. Investigators also found notes embedded in the attack scripts justifying the intruder's actions, which DIVD called another sign of an AI-driven operation.

Data risk and the response

DIVD says it is still investigating exactly which data of which volunteers is affected. It warned that the theft raises the risk of social engineering, because it makes it easier for someone to pose as a DIVD'er, and advised anyone receiving a contact request from a DIVD address that "feels slightly off" to verify it via [email protected]. Security researchers praised the transparency; VulnCheck's Patrick Garrity said it would be nice if all organizations were this transparent about their security incidents.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.