Back to Is it Real? Brand Library
PPaperCut logo

PaperCut

Targeting IT administrators with fake urgent security advisories and patch notifications, designed to harvest admin credentials or deliver malware.

Official indicators

P
PaperCut<support@papercut.com>
To: you@example.com
Verified
For your security, please View PaperCut Security Bulletins to complete this action.

What real PaperCut communications look like

  • PaperCut publishes security advisories at papercut.com/kb/Category/SecurityBulletins/ — always verify there first
  • PaperCut does not proactively email administrators to apply patches via a link
  • Legitimate software updates are applied through the PaperCut admin console directly, not via email instructions
  • Official support contact is through your PaperCut reseller or support@papercut.com — verify using contact details from papercut.com, not from an inbound email
  • PaperCut will never request remote access via an unsolicited email or ask for admin credentials over email

Common spoof patterns

  • Fake "urgent security advisory" emails mimicking PaperCut's bulletin style, pressuring admins to click a patch link immediately
  • "Critical vulnerability — action required" emails targeting organisations known to use PaperCut NG/MF
  • Fake admin console login pages designed to harvest credentials
  • Emails posing as PaperCut support requesting remote access to "apply a fix"
  • Lookalike domains such as papercut-security.com, papercut-update.com, or papercut-support.net

Note for NZ organisations

PaperCut is widely deployed in NZ schools, universities, and businesses. Active zero-day exploitation of PaperCut NG/MF was confirmed in August–September 2026 — making fake advisory emails especially plausible right now. Treat any unsolicited PaperCut security email with heightened suspicion.