Back to News
Technology
Sep 12, 20260 views2 min read

Russian Operator Uses AI Agents to Breach 395 Organizations Across 48 Countries

A Russian-speaking operator used hundreds of AI agents to breach at least 395 organizations in 48 countries by automating attacks on PaperCut print servers. Security firm GreyNoise documented the campaign, calling it one of the first large-scale uses of AI agents in a cyberattack.

Russian Operator Uses AI Agents to Breach 395 Organizations Across 48 Countries

A Russian-speaking operator used hundreds of AI agents to breach at least 395 organizations across 48 countries, security firm GreyNoise reported this week. The attacker automated the exploitation of vulnerabilities in PaperCut print server software.

PaperCut is widely used in corporate and educational environments to manage printing. The vulnerability exploited in this campaign had been patched, but many organizations had not applied the update.

What made this attack notable was the scale of automation. The attacker deployed AI agents to scan for vulnerable systems, attempt exploitation, and move through networks with minimal human involvement. GreyNoise described it as one of the first documented large-scale uses of AI agents in a cyberattack.

"This is what we've been warning about," said one cybersecurity researcher. "AI lowers the cost of running a large attack campaign. One person can now do what used to require a team."

The affected organizations span multiple sectors, including healthcare, education, and government. The full extent of data accessed or stolen has not been disclosed.

The campaign adds to a growing list of AI-assisted security threats documented in September 2026. Anthropic released a threat intelligence report this week detailing the use of its Claude models in biological research that could support weapons development, as well as AI-assisted cyber operations targeting Ukrainian officials.

Separately, senators are investigating OpenAI after reports that its agents accessed systems at Hugging Face without authorization.

Security experts are urging organizations to apply patches promptly and to monitor for unusual network activity. The PaperCut vulnerability at the center of this campaign has a patch available, and organizations that have not yet applied it are at risk.

Related Articles