Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: + –
8 minutes reading time (1612 words)

An AI Agent Hacked a Security Nonprofit Through Its Helpdesk: Lessons from the DIVD Breach

A cybersecurity nonprofit whose entire mission is warning others about vulnerabilities has itself been breached, and it believes an AI agent did the hacking. On September 24, 2026, the Dutch Institute for Vulnerability Disclosure (DIVD) announced that attackers had broken into its systems. Over the following week, DIVD revealed that the attacker exploited two previously unknown vulnerabilities in Zammad, a popular open-source helpdesk and ticketing system, and stole volunteer data. Zammad has not yet released official patches.
If your organization runs Zammad, or any self-hosted helpdesk, this story is directly relevant to you. And even if you do not, it offers one of the clearest real-world looks, yet at what an AI-driven attack can look like and how a well-run organization responds to one. 

What Happened at DIVD?

DIVD is a Netherlands-based volunteer organization that scans the internet for vulnerable systems and alerts their owners. After detecting suspicious activity, DIVD went into what it called "full incident response mode." It blocked access to its infrastructure, started a forensic investigation with a third-party incident response team, notified the people directly affected, and reported the incident to the Dutch data protection authority (Autoriteit Persoonsgegevens), the National Cyber Security Centre, and law enforcement.

DIVD then did something many organizations avoid: it published regular, detailed public updates. Its stated policy was to be "open, transparent and honest, even if it sucks." Those updates revealed:

  • The attacker was likely an agentic AI, meaning an AI system that takes actions on its own rather than simply answering questions.
  • The attack exploited two zero-day vulnerabilities in Zammad, identified with help from Merlon Security and now reported to the Zammad developers.
  • Volunteer data was accessed and stolen, including DIVD email addresses and possibly contact details.

DIVD has advised anyone who receives suspicious communications claiming to be from DIVD to verify them through an official DIVD email address and has promised its next public update no later than October 9, 2026.

The Two Zammad Vulnerabilities, Explained 
On their own, each of these flaws is serious. Chained together, they take an attacker from outside the helpdesk portal to complete control of the server it runs on.
Vulnerability Type What it allows
CVE-2026-102489 Session hijack leading to remote code execution An attacker can run their own code on the Zammad server remotely
CVE-2026-102490 Local privilege escalation The local Zammad user account can escalate to full root (administrator) control
Two zero-days chained together: from helpdesk portal to root access to stolen data.

Is Your Zammad Version at Risk?

According to DIVD, the vulnerabilities are exploitable in Zammad 6.3.0 through 6.5.4. The flaws are also present in Zammad 7.0.0 through 7.1.3, but DIVD says they are not exploitable in those versions "due to environment conditions." Zammad has not yet released fixes.  

Version 7 reduces the immediate risk, but official patches are still needed.

DIVD's guidance is direct: update to Zammad version 7 as soon as possible, or take your instance offline. DIVD is also actively scanning the internet for vulnerable Zammad servers and notifying their owners, so do not be surprised if your organization receives such a notice.

Why Helpdesk Systems Are Such Attractive Targets

It is easy to think of a ticketing system as a back-office tool. Attackers see it differently. A helpdesk often contains:

  • Names, email addresses, and phone numbers for customers and employees
  • Internal conversations about problems, outages, and security issues
  • Screenshots, attachments, and configuration details
  • Passwords, license keys, or access codes that someone shared "just this once" in a ticket
  • A trusted email address that customers expect to hear from

That last point matters. If an attacker controls your support system, they can send phishing messages that come from a real, trusted address and reference real ticket numbers. That makes the follow-on scams far more convincing.

What the AI Angle Really Means

Headlines have focused on the "AI hacker" angle, and SANS NewsBites editors offered a healthy range of views. John Pescatore warned against letting "agentic AI" become the new buzzword excuse, much as "Advanced Persistent Threat" once was. The core problem, he noted, was two exploitable vulnerabilities.

Ed Skoudis highlighted a fascinating detail from DIVD's updates: the attacking agent was "loud," "messy," and prone to "overexplaining in its comments." If that assessment holds up, it suggests that machine-speed attacks are not necessarily stealthy attacks. An AI agent may generate a large amount of observable activity very quickly. That makes good logging, telemetry, and rapid containment more valuable than ever, because there may be plenty of evidence to catch, if someone is watching.

Lee Neely's takeaway was the most practical: assume attackers will use every resource available, including AI, to find weaknesses, and go back to the basics. Defense in depth. A web application firewall. Phishing-resistant MFA. Monitoring and alerting. Keeping systems updated and securely configured. Not exposing management interfaces.

A Model for Breach Communication 

Several editors praised DIVD's transparency. As editor Brian Honan put it, organizations are rarely judged simply for being the victim of a cyberattack, but they are judged on how they respond. DIVD's frequent updates showed what good incident communication looks like.

DIVD's response followed the classic incident response playbook, with public communication at every stage.

Every business should ask itself: if our helpdesk or another key system were breached tomorrow, would we know who to call, what to say, and how to reach affected customers if our main website or email were down?

How to Protect Your Organization Now

Whether you run Zammad or a different helpdesk platform, these steps reduce your risk:

1. Upgrade Zammad to version 7 now. If you cannot upgrade immediately, take the instance offline or block access from the internet. Watch for official Zammad patches and apply them as soon as they are released.
2. Check for signs of compromise. Review server and application logs for unusual sessions, unexpected processes, new accounts, or large data transfers, especially if your instance was internet-facing.
3. Keep management interfaces private. Place admin panels and agent portals behind a VPN, zero-trust access, or a web application firewall.
4. Require phishing-resistant MFA for every helpdesk agent and administrator account.
5. Keep secrets out of tickets. Train staff not to share passwords or sensitive data in tickets, and clean up old tickets that contain them.
6. Invest in monitoring and alerting. Fast, noisy attacks are easiest to stop when logs are centralized and someone is watching around the clock.
7. Write your breach communication plan now. Decide who notifies customers, regulators, and partners, and how, before you need to.

Not sure whether your helpdesk is exposed, or who is responsible for patching it? LBT Technology Group, LLC. can assess your self-hosted applications, check for signs of compromise, and put monitoring in place that catches attacks early. Reach out to our team for a quick review.

The Bottom Line 

The DIVD breach is a preview of a world where attackers, human or AI, find and chain zero-days faster than ever. The defense is not exotic. It is the fundamentals done consistently: patch quickly, limit exposure, require strong authentication, watch your logs, and plan how you will communicate when something goes wrong. If you run Zammad, upgrade to version 7 today.

Frequently Asked Questions

Sources & Further Reading

...

Zammad Zero-Days Exploited in AI-Powered DIVD Hack - SecurityWeek

Two Zammad zero-days, CVE-2026-102489 and CVE-2026-102490, were exploited in an AI-powered attack targeting DIVD.
...

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit - Help Net Security

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two Zammad zero-days.
...

AI Agent Hacked Cybersecurity Nonprofit DIVD via Zammad Zero-Days; Root Flaw Unpatched

Zammad zero-day vulnerabilities CVE-2026-102489 and CVE-2026-102490 were chained by an autonomous AI agent to breach cybersecurity nonprofit DIVD on September 21, 2026, reaching root access in
Cybersecurity Threat Advisory: WordPress "Click2Sh...
Your Backups Might Not Save You: What a New Ransom...

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024