Skip to the content.

DIVD-2026-00014 - When, not if...

Our reference DIVD-2026-00014
Case lead DIVD Crisis Management Team
Author Various
Researcher(s)
CVE(s)
Product [nil]
Versions [nil]
Status Open
Last modified 30 Sep 2026 21:26 CEST

Summary

DIVD got hacked through AI agents and is currently investigating the breach. Incident investigation is ongoing.

We have identified that the hackers got in via two 0-day vulnerabilities in Zammad. We have assigned the CVE IDs CVE-2026-102489 and CVE-2026-102490 to these vulnerabilities and started case DIVD-2026-00015 to do target and victim notification for these two known exploited vulnerabilities.

We will update this page shortly with more information on the incident.

Timeline

Date Description
21 Sep 2026 First access by malicious actor on DIVD systems
22 Sep 2026 DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked
22 Sep 2026 Incident response team formed and forensic investigation started together with Merlon Security
30 Sep 2026 Publication of casefile
01 Oct 2026 (Planned) publication of overview of research into which data is compromised and which data is not.
gantt title DIVD-2026-00014 - When, not if... dateFormat YYYY-MM-DD axisFormat %e %b %Y section Case DIVD-2026-00014 - When, not if... (still open) :2026-09-22, 2026-10-07 section Events First access by malicious actor on DIVD systems : milestone, 2026-09-21, 0d DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked : milestone, 2026-09-22, 0d Incident response team formed and forensic investigation started together with Merlon Security : milestone, 2026-09-22, 0d Publication of casefile : milestone, 2026-09-30, 0d (Planned) publication of overview of research into which data is compromised and which data is not. : milestone, 2026-10-01, 0d