Cybersecurity · Sunday, 13 September 2026
One person's AI helpers broke into 395 organisations. Two hundred of them were schools.
A single attacker used hundreds of automatic AI helpers to attack two flaws in printing software that PaperCut had already fixed, reaching at least 395 organisations in 48 countries. Elsewhere two law firms and the banking app Revolut lost other people's documents without anyone breaking their systems at all.
395
organisations broken into, across 48 countries
204 of them were schools and colleges
26 seconds
in which 11 organisations were compromised
one attack, run by many copies of a helper at the same time
7 minutes
from first access to full control at one US high school
the attacker also left some victims alone for days before going further
12 days
between PaperCut's emergency fixes and the report naming the victims
the fixes went out on 28 August and GreyNoise reported on Wednesday
The lead story — what happened
-
One person broke into at least 395 organisations in 48 countries using hundreds of automatic AI helpers.
[1] -
Schools and colleges were 204 of the victims. The United States had 98 and the United Kingdom 59.
[1] -
The way in was two flaws in PaperCut, printing software that schools, councils and companies run on their own servers.
[1] -
PaperCut published emergency fixes for both on 28 August, the day after a school-sector customer reported a break-in.
[1] -
The attacker was not fast at any one break-in. The helpers ran the same attack side by side, and 11 organisations were compromised in 26 seconds.
[1] -
At one American high school, the attacker went from first access to full control of the school's accounts in seven minutes.
[1] -
GreyNoise, the threat-tracking firm that traced the campaign, says the attacker went from an empty workspace to a first real break-in in under four hours.
[1] -
The person running the helpers told them to skip 28 countries, led by Russia, China, Hong Kong, Thailand and Iran. Some helpers attacked organisations in those countries anyway.
[1] -
That skip list is the one criminal crews normally use, which is why GreyNoise thinks the person is likely Russian-speaking.
[1] -
Nobody knows what the access is for. Many victims were left untouched for days, and GreyNoise says the access may be handed on to other crews.
[1] -
In at least one case, Cloudflare's web firewall, which filters traffic before it reaches a server, blocked the attacker.
[1] -
PaperCut replaced the emergency fixes with full maintenance releases on Thursday.
[1]
Who is involved
-
GreyNoise
an American firm that watches internet-wide scanning and attacks; it traced this campaign and counted the victims
-
PaperCut
an Australian company whose printing software runs in schools, councils and companies; it patched the two flaws on 28 August
-
Greenberg Traurig
a US law firm with more than 3,200 lawyers; documents taken from it were posted on the dark web
-
Revolut
a British banking app with no branches; it sent customer identity documents to someone posing as a government agency
How it unfolded
-
27 Aug a school-sector customer reports the first break-in to PaperCut
-
28 Aug PaperCut publishes emergency fixes for the two flaws
-
31 Aug GreyNoise traces the campaign's control to an internet address it had watched since July
-
Wed GreyNoise reports 395 victim organisations in 48 countries
-
Thu PaperCut replaces the emergency fixes with full releases
Where this points
Watch whether these break-ins turn into ransom demands; GreyNoise says the access may be passed to extortion crews.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
PaperCut published its emergency fixes on 28 August.
The law firms Greenberg Traurig and Eckert Seamans both say documents left after someone was tricked, not after their systems were broken.
One person used hundreds of AI helpers to break into 395 organisations.
The UK government gave Apple and Google three months to block images of child nudity on phones.
The rest of the day
13 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Law firms robbed through their own lawyers
Greenberg Traurig, a US law firm with more than 3,200 lawyers, said on Thursday that an outsider reached a limited number of documents and posted them on the dark web.
[2] It told the state of Vermont that Social Security information was exposed, while insisting its own systems were never broken into.[2] Eckert Seamans, a Pittsburgh firm, faces two proposed class actions after disclosing that one of its lawyers was tricked into granting access in August.[2] The law firm BakerHostetler counted nearly 60 law-firm incidents last year, almost double the year before.[2] Why it matters — Law firms hold other companies' deals, lawsuits and investigations, so one trick reaches clients who never chose the firm's security. Quinn Emanuel, McDermott Will and Schulte, Herbert Smith Freehills Kramer and Goodwin Procter have all disclosed breaches in recent weeks.
[2] -
03
Revolut sends passports to fake officials
Revolut, a British banking app with no branches, confirmed on Saturday that customer information went to an outsider who sent fraudulent requests.
[3] The requests were sent from the email domain of a real government agency.[3] A message from a government domain is normally taken as official.[3] The data included dates of birth, postal and email addresses, phone numbers, and copies of passports and driving licences.[3] Revolut says it blocked the address, alerted the agency, law enforcement and the regulators, and that accounts and money are untouched.[3] Why it matters — A passport copy cannot be changed the way a password can, so the people affected carry this for years, and Revolut has not said how many there are.
[3] The company is preparing a public share listing at a valuation of up to $200 billion.[3] -
04
Claude used for weapons work, Anthropic says
Anthropic, the American maker of the Claude AI models, published a report on Thursday on how people misused them.
[6] It says a China-based user built software to rank air-defence targets and model radar jamming, with one simulation holding 12 targets in Taiwan.[6] A group in northern Yemen used Claude to help write software for a guided rocket and a planned longer-range missile.[6] Russia-based users worked on control software for swarms of small attack drones.[6] Anthropic banned the accounts behind the Taiwan work and says it has no evidence the Yemen group fielded a weapon.[6] Why it matters — China's foreign ministry said it was unaware of the report and opposes smears against the country.
[6] Every part of this account is the company's own, and nobody outside it has seen the accounts.[6] -
05
Russian spies used AI to dodge detection
Anthropic says a Russia-linked spying group used Claude against more than 20 government, intelligence, diplomatic and defence bodies.
[5] Its methods match Midnight Blizzard, a group Western agencies attribute to Russia's foreign intelligence service.[5] It got into the mailboxes of two drone-parts makers, then targeted a military drone maker and took a complete software kit for its vision system, which it used Claude to pick apart.[5] Anthropic says most operations it disrupted were run by AI, with humans as overseers.[11] When security products flagged its tools, it used Claude to change them and put them back.[5] Why it matters — Anthropic's own conclusion is that this pushes the cost back onto defenders, because a new detection used to slow an attacker down and can now be bypassed faster than defenders ship the next one.
[5] It also published technical fingerprints so other security teams can search their own records.[5] -
06
Meta ran hundreds more child-abuse adverts
Researchers at the Tech Transparency Project found more than 250 further advertisements containing child sexual abuse material on Facebook, Instagram and Threads since the start of August.
[7] Meta had removed about 50 such adverts a month earlier and said new AI tools would catch them.[7] Some of the new ones used photographs of real children, including one taken from a European royal family's official website.[7] Many led to apps that undress people in pictures.[7] All were reported to the US centre that collects child-abuse reports.[7] Why it matters — Meta's own rules say every advert is reviewed before it runs, and these ran anyway.
[7] The researchers say that in some cases Meta took a week to act on an advert they had reported while it was live.[7] -
07
UK writes a law after Apple and Google miss a deadline
In June the UK government gave technology companies three months to make taking, viewing or sharing images of child nudity impossible on their devices.
[8] The deadline passed on Tuesday, and the culture secretary, Lisa Nandy, told lawmakers the work done does not meet the scale of the problem.[8] Under the planned law, companies that do not build the protections into phones and tablets sold in the UK would face fines, and their bosses could face criminal liability.[8] Apple says it has shared future plans with officials.[8] Why it matters — The messaging app Signal accused the UK government in June of using child safety to rush surveillance powers into law.
[8] Nandy says she will reassess the legislation if the companies ship something while it is being drafted.[8] -
08
Huawei goes on trial in New York
The US criminal trial of Huawei, a very large Chinese telecommunications company, opened in a Brooklyn federal court on Wednesday.
[9] A Justice Department lawyer told jurors the company stole trade secrets from five American firms, including router software from Cisco and a phone-testing robot arm from T-Mobile.[9] Huawei's lawyer said the case is about competition rather than conspiracy, and that prosecutors are cherry-picking isolated events.[9] The case began with a 2018 indictment over sanctions and bank fraud, and is expected to last three months.[9] Why it matters — The charges include racketeering, which treats the alleged thefts as one long business practice rather than separate incidents by individual staff.
[9] -
09
Invisible characters slip phishing past filters
Microsoft says attackers hid invisible characters inside ordinary words, such as funding, in phishing emails.
[4] A filter reads a word that is not the word the person sees, so mail trained to spot money scams does not match.[4] The campaign ran from February to June and sent as many as 2.37 million messages a day.[4] The same trick is used to smuggle hidden instructions into AI systems.[4] Why it matters — Microsoft says the trick can disrupt filters that learn from patterns in past mail.
[4] -
10
Phone-shop worker jailed for SIM swaps
Kenneth Carter, a former AT&T employee in the United States, was sentenced to 16 months in prison for moving customers' phone numbers onto criminals' SIM cards.
[4] A SIM swap moves a phone number onto a new card, so texts sent to that number reach whoever holds the new card. The criminals used that to take over bank accounts.[4] Three victims faced intended losses of nearly $600,000.[4] Carter was typically paid $1,000 to $2,000 for each swap.[4] Why it matters — Carter abused his role at a phone store, which is the place a number gets moved to a new card.
[4] -
11
Water plant controllers sit outside every scan
Intruders reached water and wastewater treatment equipment across the United States in July, and the US cyber-defence agency counted more than 100 compromised systems.
[10] Most of that equipment was reachable over public mobile networks rather than the city's own network, so no city asset list or network scan included it.[10] A pump station in Clayton County, Georgia failed at about 1am on 27 July, and the boil-water notice was lifted the next day.[10] Waco's former chief information officer wrote that those mobile links appear nowhere except the phone bill.[10] Why it matters — He argues that in a typical city nobody is accountable for the whole shared network, and that the plant answers to public works rather than to an IT department.
[10] He now advises a company selling the technology he bought while he ran the city's systems, and the article says so.[10] -
12
FBI warns of permission scams that need no password
The FBI, the United States' federal police force, warned that attackers are getting lasting access to accounts without stealing a password.
[4] They impersonate someone the target trusts and send them to an app that asks permission to read their email and files.[4] The permissions look normal because real apps ask for the same ones.[4] The FBI calls the access persistent, meaning it keeps working after the first sign-in.[4] Why it matters — The FBI says no password is stolen in this, so the account's own password was never the thing protecting it.
[4] -
13
WordPress add-on flaw under attack
Attackers are exploiting a flaw in Super Forms, an add-on that collects contact and order forms on WordPress websites.
[4] The flaw lets a stranger with no account upload a file to the site.[4] That can hand over control of the whole website.[4] A fixed version, 6.3.314, is available, and whoever runs the site has to install it.[4] Why it matters — The advice is to update to 6.3.314, and until each site's owner does that, the site stays open to it.
[4] -
14
Devices made to leak sound by radio
Researchers demonstrated an attack they call InjectEave, in which a radio signal aimed at an ordinary device makes its electronics leak information.
[4] They tested 11 commercial products, including headphones, office phones, smart fans and lamps.[4] They recovered private audio in some cases, and in others could tell whether an appliance was switched on.[4] Nothing had to be touched or modified.[4] Why it matters — The researchers showed it in tests on their own equipment, and it describes a way in that no software update would close.
[4]
Attacks copy themselves. Repairs are installed by hand.
One attacker set hundreds of automatic helpers on a flaw that was fixed twelve days earlier, and every organisation that had not installed the fix was found within minutes.
The twist
The attacker did not get better at breaking in. He got faster at doing the same break-in four hundred times, and the people installing the fix work at the speed they always worked at.
How it works
- A flaw is found and a fix is published
- The fix has to be installed, machine by machine, by whoever owns each one
- The attacker writes one working attack, then makes copies of a helper that runs it
- Each copy costs almost nothing, so every machine still missing the fix is reached at once
- The owners' side of the work takes as long as it always did
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
Russian spies using AI to dodge detection
the same step repeats: the attacker's side of the loop is now automatic, while a new detection still has to be written and shipped by people
-
Invisible characters slipping phishing past filters
2.37 million messages a day were generated, and the filter that would catch them is updated by hand
-
Meta running hundreds more child-abuse adverts
the adverts were made in bulk by software, and the review that was supposed to stop them is the slow, human part
-
The WordPress add-on flaw under attack
the fixed version exists and is being attacked anyway, because each site owner installs it separately
Where you've seen this
Junk mail
printing a million letters got cheap long before opening them did
Parking tickets
a camera issues thousands a day and one clerk hears the appeals
Exam cheating
one leaked answer sheet copies instantly, and every re-sit has to be marked by a person
The catch
Speed only helps an attacker where a fix exists and has not been installed. The law-firm break-ins and the Revolut requests needed no flaw at all, so nothing about them would have been slower.
And the whole of it
Each of those 204 schools has one or two people who do the updating, alongside everything else they do. Almost every machine any of us rely on is patched by somebody in that position, and none of them is told which flaw is being copied this week.
What is really going on
One person broke into 395 organisations this week by making copies of an automatic helper. Every victim was a machine whose owner had not installed a fix published on 28 August. The week's other two big data losses needed no flaw at all: a lawyer at Eckert Seamans was tricked into granting access, and Revolut answered fake requests sent from a real government email address.
Why it works on us — Saying that a firm's own systems were never broken into is a statement about equipment, and it is heard as a statement about whether anybody's documents left.
Who gains
-
The attacker behind the 395 break-ins
— Copies of a helper did the work, so one person now holds access to at least 440 servers that can be sold on.
[1] -
Ransomware and extortion crews
— GreyNoise says the access may be handed to affiliates or data-theft groups, who would then not have to find a way in themselves.
[1] -
Whoever bought SIM swaps from Kenneth Carter
— They paid $1,000 to $2,000 a time for account takeovers that no software flaw would have given them.
[4] -
Apple and Google
— Three months passed with nothing shipped, and the UK government's answer is a law that still has to be written and passed.
[8] -
Meta
— The abusive advertisements were paid placements, and they ran until researchers reported them.
[7] -
Security teams anywhere
— Anthropic published technical fingerprints of the Russia-linked campaign, so anyone can search their own records for it.
[5]
Who pays
-
The 204 schools and colleges on the victim list
— They run PaperCut on their own servers, so installing the 28 August fix was their job, and break-ins were still landing twelve days later.
[1] -
Revolut customers whose passports were copied
— A passport scan cannot be changed after it leaks, and Revolut has not said how many people it sent.
[3] -
Clients of Greenberg Traurig and Eckert Seamans
— Social Security information and dates of birth were exposed by firms they hired for legal work, not for holding data.
[2] -
The children whose photographs were used in Meta's advertisements
— Researchers identified four real minors, including a teenager with a public account on one of Meta's own platforms.
[7] -
People served by Clayton County's water authority
— A pump station failed at about 1am on 27 July and a boil-water notice ran until the next day.
[10] -
Bank customers whose numbers Carter moved
— Three faced intended losses of nearly $600,000 after their phone numbers were moved onto cards the criminals held.
[4]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
What the 395 break-ins are for.
GreyNoise says the attacker left many victims untouched for days and may hand the access on, and no ransom demand has been reported.
[1] -
02
Who the attacker is.
GreyNoise infers a Russian speaker only from the list of 28 countries the helpers were told to skip, and no authority has named anyone.
[1] -
03
How many Revolut customers lost identity documents.
Revolut gave no number, and the list of what was taken comes from a TechCrunch report rather than from the company.
[3] -
04
Whether any weapon in Anthropic's report was ever built.
Anthropic says of the Yemen group that it has no evidence a weapon was fielded and that its safeguards blocked many requests but not all, and nobody outside the company has examined the accounts.
[6] -
05
How the Eckert Seamans lawyer was tricked.
The firm has said only that a lawyer was the target of a social engineering attack in August, and it did not answer questions.
[2] -
06
How many abusive advertisements are still running on Meta's platforms.
The figure of more than 350 since late last year is what the researchers found, not a total, and Meta has published no count.
[7] -
07
Who broke into the US water systems in July.
No federal agency has attributed those incidents to anyone, and the advisory that names Iranian-linked actors covers a separate set of intrusions.
[10] -
08
Whether Apple and Google will build the child-nudity blocking without a law.
The UK culture secretary says she will reassess the legislation if they do, and neither company has said what it will ship or when.
[8]
In at least one of the 395 attacks, Cloudflare's web firewall blocked the attacker before the attack reached the server. PaperCut replaced its emergency fixes with full releases on Thursday.
Also true today
- Anthropic published the technical fingerprints of the Russia-linked campaign, so any security team can search its own records for the same activity.
- Kenneth Carter, who moved customers' phone numbers onto criminals' SIM cards for $1,000 to $2,000 a time, was sentenced to 16 months in a US prison.
More from Cybersecurity
Across the beats