Detect Deepfakesby Resemble AI
Agentic AI attack

PaperCut breaches by an AI agent swarm

GreyNoise documents an agent swarm compromising PaperCut servers across 395 organizations.

Incident date
Aug 31, 2026
Source report date
Sep 9, 2026
Target
PaperCut customer organizations
Agent type
Multiple AI agents
Agent role
Used by the attacker
Updated Sep 23, 2026 · 1 min read

GreyNoise reported that a campaign beginning August 31, 2026 compromised at least 440 PaperCut servers across 395 identified organizations in 48 countries. Its September 9 investigation attributed the activity to a likely Russian-speaking operator using hundreds of AI agents.

The agents combined a DeepSeek model with the Codex harness and security tools. Codex supplied the agent framework; GreyNoise explicitly distinguished it from the model provider. After testing in a lab, the operator directed exploitation against real organizations. This record concerns those unauthorized intrusions.

The campaign obtained domain administrator privileges at 12 organizations. Where those privileges were achieved, investigators observed theft of directory credentials. Other compromised organizations had not suffered the same level of access at the last observation.

GreyNoise could not determine whether the operator intended to sell access or pursue further theft or ransomware. The researchers coordinated victim notifications. The source establishes real compromise, but does not establish completed ransomware attacks.

Evidence in the reporting

Incident evidence
compromise at least 440 instances
Agent involvement
hundreds of AI Agents

Sources