AI Agents Exploit PaperCut Vulnerabilities in Global Cyberattack

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A suspected Russian-speaking attacker used hundreds of AI agents, leveraging OpenAI's Codex and DeepSeek models, to autonomously exploit vulnerabilities in PaperCut print management software. The campaign compromised 440 servers across 395 organizations in 48 countries, rapidly gaining domain administrator access and enabling credential theft and unauthorized control.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves explicit use of AI systems (AI agents powered by OpenAI's Codex and DeepSeek) in the development and execution of cyberattacks that have already caused harm to hundreds of organizations. The harms include unauthorized access, potential data breaches, and operational disruption, which fall under violations of rights and harm to communities and organizations. Since the harm has materialized and the AI system's involvement is direct and pivotal, this qualifies as an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
SafetyRobustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Economic/PropertyReputational

AI system task:
Content generation


Articles about this incident or hazard