A global cyberattack targeting PaperCut, a software used for managing printing and scanning in businesses, was carried out by a cybercriminal using hundreds of AI agents. The attack compromised at least 11 organizations within seconds and affected 395 victims across 48 countries. According to GreyNoise, a cybersecurity firm, the attacker, likely based in Russia, used AI tools to rapidly exploit vulnerabilities in the software and spread the attack globally. The operation began on August 31, with the first successful intrusion achieved within hours of the attack's initiation. The attacker exploited two recently disclosed software vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which affected PaperCut NG and MF. These flaws allowed unauthorized access to systems. To prepare, the attacker set up a lab with a vulnerable version of the software and an Active Directory server, testing his exploits until he achieved remote code execution and stole login credentials. In parallel, he used Netlas, an online search tool for exposed systems, to identify PaperCut servers connected to the internet. PaperCut often runs on Windows servers with high privileges, making a compromised system a gateway to more critical parts of a network. GreyNoise recorded at least 440 instances of PaperCut being hacked across 395 organizations. Credentials were stolen from 280 systems, and sensitive Windows or Active Directory information was obtained from 147. In 12 cases, the attacker gained full control over an organization’s network by obtaining domain administrator rights. The attack was executed with remarkable speed. The first victim was compromised in less than four hours, and domain administrator rights were obtained just two hours later. Once the attack expanded, 11 companies were hacked in 26 seconds. This rapid pace was made possible by the use of hundreds of AI agents operating through the Codex environment, powered by a DeepSeek model. These AI tools accelerated the process of developing, testing, and using the vulnerabilities, which would normally take more human effort. Despite the AI agents’ autonomy, the attacker remained involved in setting goals and managing the operation. In some cases, the AI agents did not act for days due to a lack of direction. The attacker also specified 28 countries to avoid, though some agents did not follow this instruction. While the AI handled much of the execution, the human operator remained essential for strategic decisions. Businesses using PaperCut are urged to install the available security patches for the exploited vulnerabilities immediately. These patches can prevent similar attacks and protect sensitive systems from being compromised.