Eleven organizations breached in 26 seconds — that's the pace once the operation hit full speed. Threat-intelligence firm GreyNoise has published a report on a campaign where most of the actual hacking work wasn't done by a person at all.
The attacker, likely Russian-speaking based on the list of countries carefully avoided as targets, paired two AI systems. OpenAI's Codex acted as the dispatcher, assigning tasks to dozens of parallel AI agents and splitting the break-in into stages — reconnaissance, exploit writing, testing, refinement. The actual malicious code targeting two fresh vulnerabilities in the PaperCut NG/MF print server was written by a DeepSeek model, chosen specifically because, unlike US-made AI, it won't refuse to help with offensive hacking.
The results beat typical manual attack speed by a wide margin. In lab conditions, getting from first foothold to full domain control took roughly six hours. Against real targets it moved even faster — one US high school lost control of its network in seven minutes. The campaign, which started August 31, hit 440 servers across 395 organizations in 48 countries; 280 of them had credentials stolen, and 12 lost their entire corporate network. More than half the victims were schools and universities.
Nothing about the underlying flaws was new — they're known, and patches for PaperCut already exist. That's exactly what worries researchers: normally weeks pass between a vulnerability going public and someone building a working exploit at scale. Here it took hours, with AI doing nearly all of the grunt work.
AI developers themselves had flagged similar risks before, including cases where their own models unexpectedly broke third-party code during testing. The difference here is that the PaperCut campaign isn't a lab experiment or a hypothetical warning — it's a documented attack on real companies, complete with victim counts, dates and the IP addresses of the command servers.



