AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries

Published September 10, 2026

Attackers used AI tools to exploit two flaws in PaperCut software and break into at least 440 networks worldwide. Nearly half of the victims were schools, and the attack happened within hours of testing.

Report priority
Critical

What is known

  • Attackers first set up a test lab with vulnerable PaperCut software and Active Directory.
  • They used AI-powered tools to automate scanning for real-world PaperCut servers, then quickly exploited two flaws to gain remote control.
  • The AI helped speed up the attack by automating the search and attack steps.

What to do

If you use PaperCut NG or PaperCut MF software, check if your version is vulnerable. The attack targeted at least 440 networks worldwide, so if your school or business uses this software, you may have been affected. PaperCut has not yet released a public fix or warning for this specific attack.

Contact PaperCut support to confirm if your version is affected and ask for guidance. Watch for official updates from PaperCut about this attack and any recommended actions. Do not use untested third-party fixes or patches.

Reported details

Attackers used AI to scan for PaperCut servers, then exploited two flaws to break into 440 networks in under four hours. The attack started with a test lab, then moved to real-world targets using automated tools.

Hundreds of AI agents turned two PaperCut flaws into a fast-moving global attack. GreyNoise found that the campaign compromised at least 440 PaperCut NG/MF instances across 48 countries. Nearly half were tied to educational organizations, with 204 compromised systems in the sector. Attackers reached that scale only after first developing the intrusion.

Evidence from the campaign shows a tested process that moves from preparation to real-world exploitation, then spreads across multiple environments within seconds. Attackers tested the intrusion before scaling it GreyNoise linked the operation to a likely Russian-speaking threat actor. Researchers found the operator had built a lab containing vulnerable PaperCut software and Active Directory before attacking real systems.

Work inside the test environment allowed the actor to develop the exploitation process and verify that it worked. Potential victims were later assembled using the Netlas internet-scanning service. After testing, the operator ran the workflow through OpenAI’s Codex harness paired with a DeepSeek model.

Established offensive security tools were also available to the agents, although researchers cautioned that not every tool in the actor’s collection was seen in use. Researchers watched the operation move from an empty workspace to remote code execution against a real system in under four hours. Once the campaign was running at scale, 11 organizations were compromised within 26 seconds.

Automation allowed the attacker to repeat a prepared intrusion across multiple environments with very little time between compromises. Compromised PaperCut servers exposed credentials and domain secrets Post-compromise activity varied sharply across victims. Some intrusions stopped after access to the PaperCut server, while others reached credentials and higher-value parts of the Windows environment.

280 compromised instances had credential harvesting observed. 147 instances had operating-system or domain secrets accessed. 12 environments reached confirmed domain administrator access. One US high school went from initial access to domain administrator in seven minutes. PaperCut servers can run with powerful Windows privileges and connect to Active Directory, creating opportunities for privilege escalation after a successful breach.