DIVD Zammad volunteer-data incident

DIVD disclosed a compromise of its infrastructure and later confirmed volunteer data theft.

Last modified

Summary

  • Environment: Zammad and connected infrastructure
  • Operational impact: Datacenter access blocked during response
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

DIVD disclosed a compromise of its infrastructure and later confirmed volunteer data theft. [1]

Impact

Exposed information included volunteer email addresses; additional contact details remained under investigation. [1]

Timeline

  1. First access

    First malicious access recorded.

    [1]
  2. Detection

    DIVD blocked access after detection.

    [1]
  3. Public disclosure

    DIVD announced the compromise.

    [1]
  4. Data theft confirmed

    Volunteer-data exposure acknowledged.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

DIVD identified two Zammad zero-days enabling session hijacking, code execution and privilege escalation. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

DIVD blocked datacenter access, began external forensic work and notified Dutch authorities. [1]