PaperCut Details

    Organization Logo

    PaperCut

    Melbourne, Australia200 employees • Retail

    Industry

    Retail

    Security Incidents

    1

    PaperCut is a company that specializes in print management software designed to help organizations reduce waste, improve security, and manage printing costs. Founded in 1998 in Melbourne, Australia, PaperCut has grown to support over 100 million users worldwide, offering solutions that promote eco-friendly printing practices and efficient resource management. Their software includes features like secure print release, duplex printing encouragement, and pay-for-print policies, making printing more sustainable and cost-effective for businesses of all sizes​

    Security Incidents

    PaperCut Breach of April 2023
    Severity Score
    Moderate to Significant

    Type

    Unknown

    Summary

    In April 2023, PaperCut experienced a security incident involving vulnerabilities in their MF/NG applications, identified by Trend Micro. Despite a patch being released in March, some unpatched systems were targeted, leading to ransomware attacks by groups like Lace Tempest. PaperCut responded with an urgent outreach program, involving multiple teams and external security experts. They learned the importance of improved notification systems, enhanced penetration testing, and better communication with customers and partners. Actions include implementing security-specific alerts, increasing pene...
    Show more

    Severity

    The April 2023 security breach at PaperCut exposed critical vulnerabilities in their MF/NG applications, leading to potential customer data exfiltration and ransomware attacks. The incident highlighted significant security gaps, requiring urgent patches and extensive response efforts. This breach underscores the importance of timely software updates and robust security measures to protect sensitive data​

    Impact

    The April 2023 breach at PaperCut impacted a range of customers using their MF/NG print management software, particularly those who had not applied the March security patch. Educational institutions, healthcare providers, local governments, and other organizations relying on PaperCut's services were at risk of data exfiltration and ransomware attacks. Affected users faced potential exposure of sensitive information due to the exploitation of unpatched vulnerabilities​