A dark purple graphic with a transparent overlay of the Forward TS symbol in the right corner.

Our Blog

Why Small Businesses Get Hacked: The Printers Nobody Patches

November 1st, 2026

A hooded figure typing at a laptop behind a blue overlay of binary code, a world map, and the word LOCKED.

A small business does not get hacked because it is interesting. It gets hacked because it is reachable. Automated scanners do not read your website or count your employees - they sweep the internet for open remote desktop ports, unpatched appliances, and accounts with no second factor, then sell whatever they find to whoever pays for it.

Now look at the machine in your hallway. The copier, the multifunction printer, the one with the touchscreen that everybody uses and nobody thinks about. It is a networked computer with an operating system, a storage drive, a web server, an administrator account, and a firmware version nobody has checked since the day it was installed. It is also, in most small offices, the only device on the network that appears on no asset list, no patch schedule, and in no one's job description.

That is the gap worth closing. The useful version of the question is not "why would anyone target us," it is "how much of what attackers look for do we have." Printers are a reliable answer.

The Numbers Still Say Small Business

The 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed data breaches across 145 countries, drawn from incidents between November 1, 2024 and October 31, 2025. Read the size breakdown closely and the picture stops being ambiguous:

  • Ransomware appeared in 48 percent of confirmed breaches, up from 44 percent the year before.
  • Where the victim's size was known, 96 percent of ransomware victims were small and midsize businesses.
  • Inside small business breaches specifically, ransomware was present 88 percent of the time - against 39 percent at large organizations.
  • 69 percent of victims refused to pay, and the median ransom payment fell to $139,875.

The cost lands mostly outside the ransom. The 2026 Breach Impact Study published alongside the report, built from roughly 70,000 U.S. cyber insurance claims, ranks business interruption as the single largest loss driver - half of paid claims exceeded $83,000, and the top 10 percent ran above $920,000. Read that as the price of the days you cannot invoice, ship, or answer the phone.

What none of those reports break out is printers. That is not reassurance; it is the finding. Equipment that is never counted as an attack surface is never defended as one, and a print fleet is where a small business keeps its most forgotten computers.

What Your Printer Actually Is

Strip away the paper trays and a modern multifunction printer is an appliance running an embedded operating system, with a network stack, a web administration console, a storage device, and a set of credentials. It authenticates users against your directory, sends mail on your behalf, and writes files to your shares. Everything you would secure on a server, it does too. Almost nothing you would do to a server gets done to it.

The specifics are consistent across offices:

  • The admin console was never changed. Default credentials for the device's web interface are printed in the manual, and that interface sits on your network for anyone who reaches it.
  • It speaks protocols with no authentication at all. Raw printing on port 9100 accepts jobs from anyone who can reach the device. Add IPP, LPD, FTP, WSD, and scan-to-folder over SMB, and the printer is a service surface rather than a peripheral.
  • It holds accounts. Scanning to email requires a mailbox account. Scanning to a folder requires an account with write access to a share. Panel login requires a directory account. Each one is a credential stored on the device, usually without a second factor.
  • It is rarely patched. Firmware updates exist and are published; the device simply sits outside whatever patch cycle the rest of the network gets, because printers get treated as furniture instead of software.
  • Cloud connectors nobody remembers. Someone enabled a print-from-anywhere service so a phone could print once, and the connection outlived the reason.

What It Remembers

A compromise of the printer is not a compromise of the printer. Look at what the device is holding:

  • The address book - every client, vendor, and employee address in the company, ready for a convincing invoice or payment-change email sent under a name the recipient recognizes.
  • Scan-to-email credentials - frequently a service account with a mailbox, and the ability to read what lands in it.
  • Scan-to-folder credentials - write access to a file share, which is often one directory hop from something that matters.
  • A directory bind account - the account the panel uses to authenticate users can, in many configurations, read a great deal of the directory.
  • Cached documents - copies of jobs sit on the device's storage, along with scanned pages that were never sent and faxes that were never collected. Clearing the job from the queue does not necessarily remove it from the drive.
  • Logs - a record of who printed what, when, and where the scans went, which is useful to you and equally useful to someone mapping the office.

Nothing on that list requires an exotic attack. It requires access to a device still running the settings it shipped with.

How the Break-In Actually Reaches You

For the first time in the report's history, software vulnerabilities overtook stolen passwords as the leading way in - 31 percent of breaches now start with an exploited vulnerability. Firmware counts. So does the software inside the device that handles the print pipeline; the print spooler in Windows has been patched repeatedly for flaws that let an attacker run code as the system and then move off the machine entirely. An unpatched printer is not a dead end on your network. It is a doorway with a computer behind it.

Three paths bring that doorway into a small business.

The Port Forward Someone Opened for the Copier

Remote Desktop Protocol remains the most reliable way into a Windows network, and it is still sitting on the open internet in enormous numbers. Forescout's Vedere Labs counted roughly 1.8 million exposed RDP servers and 1.6 million exposed VNC servers in research published in 2026, with 18 percent of the RDP systems running end-of-life Windows and more than 19,000 still vulnerable to BlueKeep - a flaw patched in 2019.

In an office, this rarely arrives as a deliberate decision. It arrives as a port forward someone set up so the copier vendor could service the machine, a remote desktop session enabled so one person could work from home during a snowstorm, or a printer's web console published to the internet so staff could check supply levels from anywhere. Temporary solutions have a way of becoming the architecture. If nobody has looked at the rule list on your firewall lately, the guide to network firewalls covers what belongs there and what does not.

The Supply Order That Was Not a Supply Order

Phishing stays cheap because it keeps working, and print gives it an unusually good disguise. A message about a toner order, a meter reading, a firmware update, or an expiring service contract arrives looking like it came from your copier vendor, and asks for a click or a payment change. The 2026 DBIR notes that mobile devices carry higher click rates than desktops, and that attackers are shifting toward texts and scam calls, where the small screen hides the sender domain and there is no URL to hover over. The most expensive version involves no malware at all: a vendor invoice with new bank details, or a message from the owner who is in a meeting and needs this handled quietly.

The Third Party Holding the Contract

Third-party involvement in breaches rose 60 percent year over year and now appears in 48 percent of them. For a small business that usually means the IT provider, the payroll service, the accountant's portal, and the managed print provider. Each holds some level of access to your systems. Which accounts exist, whether those accounts require MFA, and whether they were removed when the project ended are three questions that rarely get asked out loud.

Why This Lands Harder Without an IT Department

  • No asset list. You cannot patch what you cannot name, and most offices cannot name the firewall model, the firmware version on the copier, or the last time the network storage was updated.
  • A fleet of mixed ages. Printers get bought once and kept for a decade. Somewhere in the building is a device the manufacturer stopped supporting, which means it will never receive the fix for the next flaw - and end-of-life hardware is exactly what scanners look for.
  • Backups that have never been restored. A backup that has not been tested is a hope, not a control. That applies to the device configuration too: after a wipe, somebody has to rebuild the address book and every scan destination.
  • Insurance paperwork nobody can answer. Cyber insurance renewals now ask about MFA coverage, endpoint protection, backup testing, and incident response. "We think so" is not an answer that gets a good rate.
  • One person holding the keys. When the printer admin password lives on a note behind the panel, so does the risk. When every password lives with one employee, the risk leaves with them.
  • Silence. Without logging, a breach is invisible until a customer calls or a screen turns into a ransom note. The average time to identify an intrusion is measured in weeks and months, not hours.

The Six Controls, Print Fleet First

No set of controls makes a business unhackable, and anyone promising that is selling something else. These six carry the best ratio of effort to risk removed, and every one of them touches the printer.

1. MFA on Every Account the Printer Uses, and Every Console That Manages It

Microsoft's own research found that multifactor authentication can block more than 99.2 percent of account compromise attacks, which is why attackers spend their effort on the accounts that do not have it. In print terms that means the scan-to-email account, the scan-to-folder account, the directory bind account, the device's own administrator login, and any cloud print service. Use number matching or app-based push rather than text codes where the provider supports it - text codes fall to real-time phishing proxies that relay them as they are typed - and hardware keys for administrators and anyone who can move money. Then check the exceptions, because the one service account nobody wanted to reconfigure is the one that gets used.

2. A Patch Cycle That Includes Firmware

Start with an inventory that lists every multifunction printer and copier by model and firmware version, alongside the firewalls, switches, wireless access points, network storage, and phone system. Subscribe to each manufacturer's security advisories. Treat anything a vendor has flagged as actively exploited as the first thing patched, because attackers are already using it. Replace anything the manufacturer has stopped supporting; end-of-life equipment does not receive the fix that would have saved it.

3. Remote Access That Does Not Sit on the Internet

Nothing answering on port 3389 from outside, ever. No printer web console published to the internet. Remote work through a VPN or a zero-trust gateway with MFA in front of it, vendor access granted for a window and logged rather than left open indefinitely, and a review of every port forward on the firewall - including the ones from three employees ago and the one that exists so the copier can be serviced.

4. Monitoring, and Access Control at the Device

Signature-based antivirus recognizes malware it has seen before, and modern intrusions rarely arrive as a known file. The print fleet's version of access control is straightforward and it works: badge or PIN release, so a job prints only when its owner is standing at the machine. That stops the document left in the output tray and the job pulled from the queue by somebody else, and it turns the device into a place access is granted rather than assumed - the same principle behind secure print release in municipal offices. Route device logs - print, copy, scan, and authentication - somewhere they are actually watched, which is what proactive network monitoring means in practice. An alert that arrives at 2 a.m. and is read at 9 a.m. gave the attacker seven hours.

5. Backups That Are Tested, Versioned, and Offline

Ransomware operators look for backups early, because backups are what turn a ransom demand into an inconvenience. The 3-2-1 pattern still holds - three copies of the data, on two kinds of media, with one copy offline or immutable - and versioning matters as much as the copies, since an infected file synced to a connected backup is just an infected backup. For the print fleet that means exporting device configurations so a wiped machine can be rebuilt, and enabling drive encryption and the secure erase function on anything being retired or sent out for service. Then restore something real, on a schedule, and write down what happened. We covered the fuller version of this control in backup and disaster recovery.

6. Email Filtering and Domain Spoofing Protection

Phishing is a filtering problem before it is anything else. A mail gateway configured to block known-bad senders, attachments, and links stops most of it before an inbox ever sees it, and domain authentication - SPF, DKIM, and DMARC - keeps someone from sending mail that appears to come from your address. Skip that last part and an attacker can invoice your customers in your name, from your domain, with nothing to tip them off. Print-themed phishing deserves its own mention when you brief staff, since a fake toner or service notice looks unremarkable in an inbox.

Questions Worth Asking About Your Print Fleet

Ask these of an IT or managed print provider you are evaluating, or answer them yourself if you handle it internally. Vague answers are the finding.

  1. Can you show me every device and account on my network, including the copiers, in writing?
  2. Who patches the printer firmware, and on what schedule?
  3. Is any printer's web console reachable from the internet, or still on default credentials?
  4. Which account does the copier use to send email and write scans, and what can that account reach?
  5. Is anything at my company reachable on port 3389 right now - including a port forward someone opened for a printer vendor?
  6. Does anyone look at print, scan, and login logs outside business hours, or do they wait until morning?
  7. When was the last backup restored, and who watched it happen?
  8. Which outside vendors hold credentials to my systems, and when were those last reviewed?
  9. What happens in the first hour after a suspected breach - and which of these answers can go in writing for my cyber insurance renewal?

The Printer Is the Easiest Place to Start

Printers get ignored because they seem boring, which is exactly what makes them useful to an attacker and, conveniently, what makes them cheap to fix. A print fleet that is inventoried, patched, released by badge, and logged accounts for a meaningful share of the exposure in an office your size - often the largest single item on the list, and the one that stays fixed.

Forward TS provides managed print services and managed IT services to Milwaukee-area businesses. The two work together here: firmware and device configuration handled on the print side, with patching, MFA, monitoring, tested backups, and vendor access control on the IT side, plus the documentation your insurer and your clients ask for. For one part of this in more depth, our article on print and copy security in law firms walks through the same controls in a records-heavy environment, and if you want to know how a starting point gets measured, security assessments covers that.

Start with a free audit to see what your network is exposing and what your devices are reporting, or contact us to talk through what your business needs.