Mark Ellison found the compromised device almost by accident.

He was running a routine network sweep on a Thursday afternoon, the kind of task that usually turned up nothing more exciting than an outdated firmware warning. But this time, one device stood out. A shared office printer on the third floor, the same one people used to print boarding passes and expense reports, had been sending small bursts of outbound traffic to an unfamiliar address every few hours for the past six weeks.

Nobody had noticed. Why would they? It was a printer.

That was exactly the point. The attacker hadn't broken through a firewall or cracked an employee's password. They had found a device connected to the network that nobody was actively monitoring, and used it as a quiet foothold to observe traffic and slowly map out what else was reachable from that same corner of the network.

Mark's discovery is becoming a familiar story across companies in 2026. The devices getting attackers in aren't always the ones security teams spend the most time worrying about.

The Devices Everyone Forgets

Security teams have spent years building strong defenses around the systems that obviously matter. Servers holding customer data get monitored closely. Laptops get endpoint protection software and regular patching. Email gets filtered for phishing attempts.

But every office network is also full of devices that don't fit neatly into that picture. Printers, smart TVs in conference rooms, badge readers at the entrance, HVAC control panels, old test servers nobody remembered to decommission. Each one has an IP address, each one is technically part of the network, and most of them were never included in any monitoring plan because nobody thought of them as a real risk.

That is exactly why attackers have started favoring them. A compromised laptop trips alarms quickly because it is watched closely. A compromised printer can sit quietly for weeks, doing nothing more dramatic than passing small amounts of traffic back to an attacker, because nobody is looking.

Following the Trail

Mark brought the finding to his team lead, a methodical woman named Claire Whitfield who had spent years building out the company's monitoring stack. Claire's first question wasn't how sophisticated the attack was. It was simpler and more uncomfortable. How many other devices like this printer did they have sitting on the network with no visibility at all?

The answer, once her team did a full inventory, was more than two hundred. Badge readers, conference room displays, a handful of forgotten test servers still running years-old software, and a dozen IoT sensors installed by a facilities team that had never looped in security at all.

None of these devices individually looked dangerous. But collectively, they formed a wide, mostly invisible surface that an attacker patient enough to look for it could use to move quietly through the network, gathering information long before triggering any alert built for more obvious threats.

Claire's team traced the printer's traffic back far enough to understand the attacker's approach. It wasn't trying to breach anything directly from that device. It was using the printer's privileged position on the internal network to quietly observe which servers talked to which, building a map that would make a future, more direct attack far more precise.

Building Visibility Where There Was None

Fixing the problem wasn't about buying a single new tool. It meant changing how the company thought about its own network in the first place.

Claire's team started by bringing every device on the network into a single inventory, not just the ones traditionally considered endpoints. Every printer, every badge reader, every smart display got an owner assigned and a baseline established for what normal traffic from that device looked like. Anything that deviated from that baseline, even slightly, triggered a flag.

They also pushed for a policy that treated any new device connected to the network as untrusted by default until someone confirmed what it was for and who was responsible for it. That single change closed the gap that let the facilities team's IoT sensors slip in unnoticed in the first place.

It took months to build out fully, and it wasn't glamorous work. Nobody gets excited about auditing printers. But by the end of it, Claire's team had visibility into corners of the network that had been dark for years.

The Lesson in the Quiet Corners

Mark's printer wasn't a sophisticated attack. It was a patient one, built entirely around the assumption that most organizations watch their obvious assets closely and forget about everything else.

That assumption has been correct often enough that attackers keep using it. The uncomfortable truth for a lot of security teams in 2026 is that their biggest blind spot isn't a lack of powerful tools. It is the long list of ordinary, overlooked devices sitting quietly on their network that were never brought into the picture at all.

Closing that gap doesn't require a bigger budget. It requires the discipline to ask a simple question about every device connected to the network. Who owns this, and is anyone actually watching it?

Evvo Labs helps organizations build complete visibility across every device on their network, not just the ones that traditionally get attention. Our consulting teams help you inventory, baseline, and monitor the overlooked endpoints attackers are increasingly counting on.