AI Agents Broke Into Print Servers at 395 Organizations, a Security Company Says

The threat-intelligence company GreyNoise says one attacker used hundreds of automated coding agents to break into at least 440 PaperCut NG/MF servers belonging to 395 organizations in 48 countries. The campaign began Aug. 31, and GreyNoise published its account of it Sept. 9.
PaperCut NG/MF is self-hosted software that organizations use to track and charge for printing, copying and scanning. The attacker got in through two flaws in it, CVE-2026-81578 and CVE-2026-82078, GreyNoise said. The software normally runs with full system privileges on Windows and is usually connected to the directory that holds an organization's user accounts, so a break-in on a print server did not stay on the print server.
GreyNoise's analysis calls the campaign AI-orchestrated, and that characterization is the company's own. Its evidence is what it saw on its own sensor network, which draws attacker traffic onto infrastructure GreyNoise controls: the operator built and tested its exploits against a lab copy of the software, then turned hundreds of agents, built on OpenAI's Codex harness and running a DeepSeek model, on real targets. The company says the attacker went from an empty workspace to a first break-in at a real victim in just under four hours.
Not every intrusion went deep. GreyNoise says the attacker reached domain administrator, or control of an organization's Windows accounts, at 12 of the victim organizations, and that at one target a web application firewall stopped the agents outright. Its conclusion is that ordinary hardening still counts against AI-assisted attacks.
Most of the victims were in education, which GreyNoise attributes to PaperCut's customer base rather than to a choice of target; it describes the campaign as opportunistic. The company says it does not know whether the operator will use the access itself or hand it to others, and that earlier intrusions involving PaperCut have led to extortion. GreyNoise says it worked with incident response firms to notify the victims.
