DIVD Dutch Institute for Vulnerability Disclosure’s Post

Security people always say it's not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we're the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked. So what do hackers do when they get hacked? Handle it the way we think it should be handled. That is open, transparent and honest, even if it sucks. So far, we’ve been in full incident response mode, blocked access to our infrastructure and started a forensics investigation with the assistance of a third party incident response team. This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack. Careful investigation takes time and our investigation is still ongoing. At this moment we can’t rule anything out yet, so we handle this situation as a worst-case-scenario and assume breach until proven otherwise. Today we have informed the directly involved parties, reported the incident to the Autoriteit Persoonsgegevens and the National Cyber Security Centre and discussed our options with the police. Our priorities at this point are keeping our infrastructure isolated and secure, focusing on the forensics and looking after our volunteers who have worked for a safe digital society for the past years and in the meantime we learn a lot from this type of attack. Our next public update follows on Monday 28 September, or sooner if we have more to share. For questions and press please reach out to Marieke R. or communications@divd.nl. She is the spokeperson for this incident.

  • No alternative text description for this image

Dit is zó sterk. Op deze manier worden taboes doorbroken en maken we het onderwerp eindelijk bespreekbaar! Chapeau. Transparantie zoals dit helpt de hele sector vooruit, precies hoe we elkaar sterker maken. Succes met de recovery, en respect voor jullie openheid en aanpak.

Hackers assemble! Divd Leading by example as always :-) Hope this incident and its findings will be used in the upcoming academic year as a case study for students in cybersecurity, AI, Systems Engineering, Risk Management, Business Administration and legal disciplines:-)

Good luck! Goed dat jullie direct transparant zijn. Het goede van deze hack is dat ik er bij DIVD op vertrouw dat er goede learnings uitkomen die met iedereen gedeeld worden. Hopelijk worden we er daarom uiteindelijk allemaal beter van.

Sterkte, wat vervelend. Dat je er zo open over bent sterkt mijn vertrouwen🙏🏼 Wat is hiervan de impact voor jullie? Welke tool(s) is het geweest? Is het opzet of onderzoekend enthousiasme? Ik hoop dat jullie onderzoeksinfra al compleet gescheiden is van je rapportageomgeving.💻. Een werkwijze consequent blijven volgen, controleren en aansturen kan zonder externe audits hartstikke lastig zijn weet ik.

The AI agent picked the wrong target, now the whole cyber community will be coming for it and learn from it. Succes to all in solving this crisis!

Good luck and all the best. Meanwhile I'm taking notes, because most breach PR it's an example of how not to communicate ( cough Odido Nederland cough). But I have a feeling this is going to be a class A example of how organizations SHOULD response. Exactly what is stated: open transparent and best of all: sooner rather than later, even if it's still ongoing.

Dimitri van Zantvliet

Executive Leader in Critical Infrastructure | Digital Resilience, Technology & Transformation | Former CIO, CTO & CISO | NCSC Advisory Board | Board Observer & Angel Investor | LinkedIn Top-Voice

5d

Snelle recovery toegewenst!

All the best DIVD-vrienden 💛🖤 en ook hier weer een rolmodel in communicatie

See more comments

To view or add a comment, sign in

Explore content categories