The news
Reports published in September 2026 show AI-powered cyberattacks escalating in scale and speed. GreyNoise published its analysis on September 9, and Microsoft and Anthropic published reports on September 10. Together they show attackers using commercial AI agents to compromise hundreds of organizations, reaching a first victim in under four hours, and using AI to mass-produce fraud aimed at corporate finance teams.
The starkest case comes from the security firm GreyNoise. It says a single adversary, starting on August 31, used hundreds of AI agents built on OpenAI's Codex harness and a DeepSeek model to exploit two flaws in PaperCut NG/MF print-management software, CVE-2026-81578 and CVE-2026-82078. At least 440 installations at 395 organizations in 48 countries were compromised, with the education sector accounting for 204 victims.
The speed is the headline. According to GreyNoise, the attacker went from an empty workspace to running code on a real victim's server in just under four hours, and 11 organizations were compromised in 26 seconds once the campaign scaled. Help Net Security reported that credentials were harvested at 280 organizations and 12 reached full domain-administrator control. The agents also hit some countries the operator had tried to exclude. PaperCut released security updates and urged customers to keep its application server off the public internet, according to BleepingComputer and Help Net Security.
Finance teams are a parallel target. On September 10, Microsoft (MSFT) described an August 3 to 5 campaign of more than 1 million emails impersonating chief executives and finance chiefs and asking accounts-payable staff to pay invoices of nearly $50,000 by ACH bank transfer. Most targets were US-based. Microsoft said the email templates showed signs of generative-AI authorship and that it found no evidence that ServiceNow (NOW), whose name was spoofed through lookalike domains, had been compromised.
Anthropic's threat report, also published September 10 and covering December 2025 to August 2026, describes the broader pattern: criminal and state-linked groups using its Claude models for reconnaissance, exploit development, credential theft and fraud, and increasingly running multi-agent operations with little human input. Anthropic said AI has narrowed the gap between well-funded state operations and individual attackers, and it urged organizations to treat AI keys and agent integrations as seriously as production credentials.
The numbers
- PaperCut installations compromised, per GreyNoise
- At least 440
- Organizations affected, per GreyNoise
- 395 in 48 countries
- Time from empty workspace to first remote code execution
- Just under 4 hours
- Organizations compromised in 26 seconds at peak
- 11
- Invoice-fraud emails in Microsoft-tracked campaign (Aug. 3–5)
- More than 1 million
- Payment requested per fraudulent invoice
- Nearly $50,000
Why CEOs should care
For CISOs, the PaperCut case collapses the patch window. When an attacker can go from nothing to code execution in about four hours and then fan out to hundreds of victims, monthly patch cycles for internet-facing software are too slow. Inventory every externally reachable application, including unglamorous ones such as print servers, remove what does not need public access, and set a target measured in hours for emergency fixes. Detection should also account for attack patterns that look automated: many targets, near-identical steps, very short intervals.
CFOs and controllers should assume fraudulent invoices will now read as polished and plausible. The Microsoft campaign used lookalike domains and fake email threads to pressure accounts-payable staff, and Microsoft said its templates showed indicators consistent with AI-assisted development. Require call-back verification through independently sourced phone numbers for new payees and bank-detail changes, dual approval above a set threshold, and enforcement of the email authentication standards SPF, DKIM and DMARC, which help block spoofed senders.
Boards should ask two questions. First, how quickly does the company patch or isolate internet-facing systems, and is that number reported? Second, who owns the inventory of AI API keys and agent integrations? Anthropic's report says stolen AI keys are being used for further attacks and to obscure who is behind them, which makes them a liability as well as a cost line.
The bigger picture
The same commercial tools companies are adopting to automate work are being turned against them. GreyNoise's account of agents straying outside the operator's own target list also shows that attackers do not fully control their automated campaigns, which makes collateral damage more likely. For defenders, the practical conclusion is that the economics of attack have shifted: volume and speed are now cheap, so controls that rely on attackers being slow or scarce no longer hold.
What’s next
Expect more disclosures of agent-driven intrusions as security firms tune detection for automated patterns. Watch whether model providers tighten controls on how their agent tools and models can be used for scanning and exploitation, and whether regulators or insurers start asking companies to report patch times for internet-facing systems.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









