An AI Agent Swarm Hacked 395 PaperCut Instances
Articles by the same author:
1
2
3
4
On September 9, 2026, cybersecurity company GreyNoise revealed that malicious AI agents had exploited a PaperCut vulnerability to compromise 395 organizations across 48 countries. PaperCut is software used to track print, copy and scan jobs and manage their billing. Because it has extensive Windows privileges, compromising it can allow an attacker to take control of an organization’s information systems.
On August 28, 2026, PaperCut disclosed two critical vulnerabilities and released patches. The attackers exploited these flaws using hundreds of AI agents built using OpenAI’s Codex harness and a DeepSeek model, equipped with open-source offensive tools.* The cybercriminals first tested their agents in a controlled environment before allowing them to search the Internet for vulnerable targets.
“The attacker went from a blank environment to remote code execution in under four hours, then achieved domain administrator privileges two hours later. Once the campaign was launched, it compromised at least 11 organizations in 26 seconds,” the report states.
More than half of the identified victims belong to the education sector. Of these, 98 are located in the United States, 59 in the United Kingdom and 31 in France. Although the cybercriminals instructed the agents not to target organizations in 28 countries, including Russia, China and several former Soviet republics, the swarm nevertheless carried out attacks in some of them.