New Issue: Orbital Catastrophe Ahead? Read Now

Printers Can Be Hacked to Catch Fire

These devices are completely open and available to be exploited, a researcher says

Join Our Community of Science Lovers!

Two researchers at Columbia University in New York say they've found a flaw in ordinary office printers that lets hackers hijack the devices to spy on users, spread malware and even force them to overheat to the point of catching fire.

"The problem is, technology companies aren't really looking into this corner of the Internet. But we are," Salvatore Stolfo, the Columbia professor overlooking the research, said to MSNBC's Bob Sullivan, who first reported the story.

Stolfo and his fellow researcher Ang Cui sent a Hewlett-Packard LaserJet printer various bogus firmware updates. One made the fuser overheat, causing the paper in the printer to yellow and smoke until the machine shut down.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


When a tax return was sent to the printer as a print job, another bogus update secretly forwarded the document, complete with Social Security numbers, to a second computer.

"The research on this is crystal clear," Stolfo said. "The impact of this is very large. These devices are completely open and available to be exploited."

To be fair, printer vulnerabilities have been known for some time. In January, researchers at a hacker conference showed how Internet-connected printers could be hijacked to spread malware through office networks. More than a year ago, researchers showed that all-in-one printer-scanner hybrids could be made to post sensitive documents online.

The fuser-overheating flaw is similar to research recently done by Mac hacker Charlie Miller, who showed how bogus firmware upgrades to Apple laptop batteries could cause them to overheat as well.

Hewlett-Packard, which had been informed of the printer flaws before the Columbia researchers made them public, disputed that the problems were as bad as the researchers made them out to be.

"This is probably not as broad as what I had heard in their first announcement," Hewlett-Packard's Keith Moore told MSNBC. "It sounds like we disagree on what the exposure might be."

© TechMediaNetwork.com. All Rights Reserved.

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe