P

PaperCut
Targeting IT administrators with fake urgent security advisories and patch notifications, designed to harvest admin credentials or deliver malware.
Official indicators
P

PaperCut<support@papercut.com>
To: you@example.com
For your security, please View PaperCut Security Bulletins to complete this action.
Original URL: https://www.papercut.com/kb/Category/SecurityBulletins/. Click or tap if you trust this link.
What real PaperCut communications look like
- PaperCut publishes security advisories at papercut.com/kb/Category/SecurityBulletins/ — always verify there first
- PaperCut does not proactively email administrators to apply patches via a link
- Legitimate software updates are applied through the PaperCut admin console directly, not via email instructions
- Official support contact is through your PaperCut reseller or support@papercut.com — verify using contact details from papercut.com, not from an inbound email
- PaperCut will never request remote access via an unsolicited email or ask for admin credentials over email
Common spoof patterns
- Fake "urgent security advisory" emails mimicking PaperCut's bulletin style, pressuring admins to click a patch link immediately
- "Critical vulnerability — action required" emails targeting organisations known to use PaperCut NG/MF
- Fake admin console login pages designed to harvest credentials
- Emails posing as PaperCut support requesting remote access to "apply a fix"
- Lookalike domains such as papercut-security.com, papercut-update.com, or papercut-support.net
Note for NZ organisations
PaperCut is widely deployed in NZ schools, universities, and businesses. Active zero-day exploitation of PaperCut NG/MF was confirmed in August–September 2026 — making fake advisory emails especially plausible right now. Treat any unsolicited PaperCut security email with heightened suspicion.

