Russian-Speaking Attacker Turned AI Agents Loose on PaperCut, Hit 395 Organisations in Days
Hundreds of AI agents built exploits, picked targets and broke into schools and businesses across 48 countries. One US high school went from first contact to full takeover in seven minutes.

Key points
- A Russian-speaking attacker used hundreds of AI agents to attack PaperCut print-management servers, breaking into 395 organisations across 48 countries starting 31 August.
- The agents exploited two PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, and stole passwords from 280 victims and admin control at 12.
- Education was the hardest-hit sector, and the United States was the top target, followed by the UK, France, Spain and Canada.
- In one US high school the attacker went from first break-in to full network takeover in seven minutes.
- PaperCut has issued emergency fixes and admins are told to patch immediately.
An attacker who appears to speak Russian pointed a swarm of AI agents at a piece of software most people have never heard of, and used it to break into hundreds of schools and companies in a matter of days.
The software is PaperCut NG/MF, a print-management product that sits on a server inside a company's network and tracks who prints what. Because it often runs with high privileges, breaking into a PaperCut box is frequently a shortcut to the rest of the network.
That is exactly what happened here.
What did the attacker actually do?
The attacker built, tested and launched a global break-in campaign using AI, according to threat intelligence firm GreyNoise, which first reported the operation. The campaign began on 31 August and hit at least 440 PaperCut servers belonging to 395 different organisations in 48 countries.
The agents were wired up to OpenAI's Codex model and to DeepSeek, plus a scanning service called Netlas that finds internet-exposed servers. Off-the-shelf hacking tools did the rest.
The two flaws being exploited are CVE-2026-81578 and CVE-2026-82078, both in PaperCut Software and both already flagged as under active attack earlier this month. In plain English, they let an unauthenticated attacker run their own commands on a vulnerable PaperCut server.
The failure mode here is familiar: an obscure business app, deep inside the network, with admin rights nobody thought about.
How fast was it?
Very fast. That is the point of the story.
GreyNoise clocked the attacker going from an empty workspace to their first successful remote takeover in under four hours. First full domain takeover: another two hours. Once the campaign was live, 11 organisations were breached in 26 seconds. One US high school went from initial break-in to full domain administrator, meaning total control of the school's Windows network, in seven minutes.
Humans do not respond in seven minutes. That is the operational problem.
Who got hit?
| Metric | Figure |
|---|---|
| Organisations breached | 395 |
| PaperCut servers compromised | 440 |
| Countries affected | 48 |
| Credentials stolen from | 280 victims |
| Full admin control at | 12 organisations |
About half of the victims were in education. The United States was the most-targeted country, then the UK, France, Spain and Canada. The attacker told the AI agents to skip Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa, though the agents did not always follow the rules, an early sign that outsourcing your ethics module to a language model is not reliable.
Should ordinary people worry?
If your child's school, your local college or your employer used PaperCut and has not patched, staff passwords and internal files may already be in the attacker's hands. GreyNoise could not confirm the end goal, but this kind of access is normally sold on or used to launch ransomware, malicious software that locks up a company's files until a payment is made.
Watch for a password reset notice from your school or workplace in the coming weeks. If you reused that password anywhere else, change it there too.
What should admins do right now?
Apply PaperCut's emergency updates for CVE-2026-81578 and CVE-2026-82078 today, not this quarter. Assume any PaperCut server that faced the internet before 31 August is already touched, and hunt for the follow-on toolkit: Mimikatz, BloodHound, Rubeus, Impacket, NetExec and Ligolo-ng. Check domain controllers for a fresh account added to Domain Admins.
One thing the post-mortem will say: the print server was a domain admin, and nobody noticed.



