An automated AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) after exploiting an undisclosed technical vulnerability, marking what the organization describes as a fundamentally different class of attack than those it has previously encountered. The attacker deployed an autonomous AI agent to conduct post-exploitation activities across DIVD's network, with the agent independently deciding its next steps at machine speed whilst leaving behind extensive forensic evidence through what DIVD characterizes as "sloppy logic" and self-explanatory decision-making. The agent performed what researchers termed "pretty dumb things"—including sabotaging its own password-spraying attack through poor coordination—suggesting inadequate training and configuration for the operation. Whilst the full scope of the breach remains under investigation, DIVD has notified relevant authorities including the National Cyber Security Center and is withholding technical details to protect other potential victims of the same vulnerability.
The incident exposes a critical vulnerability in how CX teams approach AI agent deployment and governance. If a poorly configured agentic AI can autonomously navigate a security researcher's network, what safeguards exist within your own Zendesk, Salesforce, or Freshdesk environments where agents interact with customer data, payment systems, and internal knowledge bases? The "loud and messy" nature of this breach—leaving extensive traces precisely because the agent over-explained itself—suggests that current monitoring and logging capabilities may be insufficient to detect agentic AI behaviour in real time, particularly when agents operate at speeds that outpace human oversight. For teams already running or planning to deploy AI agents in customer-facing roles, the DIVD incident demonstrates that traditional access controls and vulnerability management frameworks were not designed for autonomous systems that make rapid, sequential decisions without human intervention between steps.
The broader implication is that CX platforms hosting agentic AI require fundamentally different security architectures than those built for human-operated systems or rule-based automation. DIVD's experience suggests that even well-resourced security organizations lack visibility into agentic behaviour patterns, raising questions about whether your organization has the detection and response capabilities to identify when an AI agent—whether deployed by you or an attacker—begins operating outside its intended parameters. As AI agents proliferate across contact centers, the absence of standardized governance frameworks means individual teams are responsible for implementing controls that security researchers themselves have not yet fully mapped.
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]