# Case update: DIVD-2026-00014 - When, not if...

> Source: <https://csirt.divd.nl/cases/DIVD-2026-00014/>
> Published: 2026-09-29 00:00:00+00:00

# DIVD-2026-00014 - When, not if...

| Our reference | [DIVD-2026-00014](https://csirt.divd.nl/cases/DIVD-2026-00014) | 
| Case lead | DIVD Crisis Management Team | 
| Author | Various | 
| Researcher(s) |  | 
| CVE(s) |  | 
| Product | [nil] | 
| Versions | [nil] | 
| Status | Open | 
| Last modified | 30 Sep 2026 18:14 CEST | 

## Summary

DIVD got hacked through AI agents and is currently investigating the breach. Incident investigation is ongoing.

We have identified that the hackers got in via two 0-day vulnerabilities in Zammad. We have assigned the CVE IDs [CVE-2026-102489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102489) and [CVE-2026-102490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102490) to these vulnerabilities and started case [DIVD-2026-00015](https://csirt.divd.nl/cases/DIVD-2026-00015) to do target and victim notification for these two known exploited vulnerabilities.

We will update this page shortly with more information on the incident.

## Timeline

| Date | Description | 
|---|---|
| 21 Sep 2026 | First access by malicious actor on DIVD systems | 
| 22 Sep 2026 | DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked | 
| 22 Sep 2026 | Incident response team formed and forensic investigation started together with Merlon Security | 
| 29 Sep 2026 | Publication of casefile | 
| 29 Sep 2026 | Publication of overview of which data is compromised and which data is not. | 

	gantt
	    title DIVD-2026-00014 - When, not if...
	    dateFormat  YYYY-MM-DD
	    axisFormat  %e %b %Y
	    section Case
	    DIVD-2026-00014 - When, not if... (still open)           :2026-09-22, 2026-10-07
	    section Events
		First access by malicious actor on DIVD systems :  milestone, 2026-09-21, 0d
				DIVD becomes aware of malicious activity. Access to all systems in the datacenter is blocked :  milestone, 2026-09-22, 0d
				Incident response team formed and forensic investigation started together with Merlon Security :  milestone, 2026-09-22, 0d
				Publication of casefile :  milestone, 2026-09-29, 0d
				Publication of overview of which data is compromised and which data is not. :  milestone, 2026-09-29, 0d
				

## What we are doing

DIVD is currently scanning for vulnerable Microtick appliances and notifying affected parties.
