Your printer is on the same network as your accounting server
A modern multi-function printer is a Linux computer with a hard drive, a web server, a scan-to-email function, and almost no patch discipline. Most networks have several. Most attackers know this.
The boring devices are the dangerous ones
Printers, cameras, smart TVs, conference room equipment, badge readers, building HVAC controls. They get installed once, default credentials, default firmware, and then forgotten for a decade.
What to do
- Inventory them. You probably have more than you think.
- Change default credentials immediately. Document the new ones somewhere a successor will find them.
- Put them on their own VLAN. They should not see your servers and your servers should not initiate connections to them.
- Block their outbound internet access except to specific endpoints they actually need.
- Review firmware annually. Yes, even printers.