Skip to content
See the World Through ScienceA project of ALLATRA

AI Agents Broke Into Print Servers at 395 Organizations, a Security Company Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A large office multifunction copier and printer against a wall in an office workroom, with a printed notice above it reading please do not turn the copier off.
A networked office copier of the kind that print management software controls. This is a context photograph and does not show any of the servers or organizations in the campaign GreyNoise describes."Do Not Turn The Copier Off" by Beige Alert, via flickr, CC-BY-2.0 · CC-BY-2.0

The threat-intelligence company GreyNoise says one attacker used hundreds of automated coding agents to break into at least 440 PaperCut NG/MF servers belonging to 395 organizations in 48 countries. The campaign began Aug. 31, and GreyNoise published its account of it Sept. 9.

PaperCut NG/MF is self-hosted software that organizations use to track and charge for printing, copying and scanning. The attacker got in through two flaws in it, CVE-2026-81578 and CVE-2026-82078, GreyNoise said. The software normally runs with full system privileges on Windows and is usually connected to the directory that holds an organization's user accounts, so a break-in on a print server did not stay on the print server.

GreyNoise's analysis calls the campaign AI-orchestrated, and that characterization is the company's own. Its evidence is what it saw on its own sensor network, which draws attacker traffic onto infrastructure GreyNoise controls: the operator built and tested its exploits against a lab copy of the software, then turned hundreds of agents, built on OpenAI's Codex harness and running a DeepSeek model, on real targets. The company says the attacker went from an empty workspace to a first break-in at a real victim in just under four hours.

Not every intrusion went deep. GreyNoise says the attacker reached domain administrator, or control of an organization's Windows accounts, at 12 of the victim organizations, and that at one target a web application firewall stopped the agents outright. Its conclusion is that ordinary hardening still counts against AI-assisted attacks.

Most of the victims were in education, which GreyNoise attributes to PaperCut's customer base rather than to a choice of target; it describes the campaign as opportunistic. The company says it does not know whether the operator will use the access itself or hand it to others, and that earlier intrusions involving PaperCut have led to extortion. GreyNoise says it worked with incident response firms to notify the victims.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

AI Agents Broke Into Print Servers at 395 Organizations, a Security Company Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.