---
title: "DIVD Zammad volunteer-data incident"
description: "DIVD Zammad volunteer-data breach: verified timeline, impact and response through October 7, 2026."
incident_type: "Vulnerability exploitation"
status: "active"
last_modified: "2026-10-07"
canonical_url: "https://www.ally.security/incidents/divd-zammad-volunteer-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/divd-zammad-volunteer-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/divd-zammad-volunteer-data-incident-2026/stix.json"
---

# DIVD Zammad volunteer-data incident

DIVD disclosed a compromise of its infrastructure and later confirmed volunteer data theft.

Last modified Oct 7, 2026 · 1 source

## Summary

- **Environment:** Zammad and connected infrastructure
- **Operational impact:** Datacenter access blocked during response
- **Financial impact:** No incident cost established in the reviewed evidence

## What happened

[DIVD](https://www.divd.nl/) disclosed a compromise of its infrastructure and later confirmed volunteer data theft. [1](#source-1)

## Impact

Exposed information included volunteer email addresses; additional contact details remained under investigation. [1](#source-1)

## Timeline

### September 21, 2026 — First access

First malicious access recorded. [1](#source-1)

### September 22, 2026 — Detection

DIVD blocked access after detection. [1](#source-1)

### September 24, 2026 — Public disclosure

DIVD announced the compromise. [1](#source-1)

### October 1, 2026 — Data theft confirmed

Volunteer-data exposure acknowledged. [1](#source-1)

### October 7, 2026 — Briefing updated

This briefing was last reviewed and updated on October 7, 2026.

## Threat Group & Attack Vector

DIVD identified two [Zammad](https://zammad.org/) zero-days enabling session hijacking, code execution and privilege escalation. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

DIVD blocked datacenter access, began external forensic work and notified Dutch authorities. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/divd-zammad-volunteer-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### DIVD-2026-00014 - When, not if...

official · Dutch Institute for Vulnerability Disclosure · Sep 29, 2026

<https://csirt.divd.nl/cases/DIVD-2026-00014/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: DIVD identified two Zammad zero-days enabling session hijacking, code execution and privilege escalation.
2. **Used Product · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: Zammad
3. **Resulted In · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: DIVD disclosed a compromise of its infrastructure and later confirmed volunteer data theft.
4. **Discovered At · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: 2026-09-22
5. **Resulted In · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: Data theft confirmed
6. **Occurred At · 100% confidence · current**  
   Data theft confirmed: 2026-10-01
7. **Resulted In · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: DIVD blocked datacenter access, began external forensic work and notified Dutch authorities.
8. **Exploited Vulnerability · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: CVE-2026-102489
9. **Exposed Data Category · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: Contact information
10. **Affected Organization · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: Dutch Institute for Vulnerability Disclosure
11. **Disclosed At · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: 2026-09-24
12. **Began At · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: 2026-09-21
13. **Exploited Vulnerability · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: CVE-2026-102490
14. **Resulted In · 100% confidence · current**  
   DIVD Zammad volunteer-data breach: Exposed information included volunteer email addresses; additional contact details remained under investigation.

</details>
