08/28/2026 | Press release | Distributed by Public on 08/28/2026 20:05
Russian-speaking cybercriminals used Cursor, an AI coding assistant now owned by Elon Musk's SpaceX, to accelerate attacks against at least seven companies earlier this year, according to cybersecurity startup Gambit Security and data Reuters reviewed.
The campaign provides another example of how commercially available AI systems are being repurposed by criminals to automate parts of sophisticated cyberattacks, raising concerns that AI agents could lower the technical and time barriers to carrying out intrusions.
Gambit said the hackers persuaded Cursor's AI agent to perform hundreds of malicious operations by falsely claiming they were conducting a security simulation. The activities included credential theft, account takeovers, network reconnaissance and attempts to exploit vulnerable systems.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Register for Nigeria Capital Market Masterclass.
"This is going to be a cat-and-mouse game," said Curtis Simpson, Gambit's chief strategy officer, describing the continuing effort by AI providers to strengthen safeguards while attackers look for ways around them.
The campaign came to light after Gambit discovered an internet-exposed server belonging to a new ransomware group called Aur0ra. The exposure allowed the Israeli cybersecurity company to examine 28 chat sessions between the hackers and one or more Cursor AI agents.
The conversations, which ran from April 8 to May 21, showed the criminals repeatedly using the AI system as an operational assistant during attacks. At one point, the hackers instructed the agent: "We need any administrator account," followed by a request to "Find any working passwords."
Reuters independently identified six of the apparent victims from the chat data. They included Christeyns, a Belgian hygiene and cleaning-products manufacturer; German garage-door maker Teckentrup; and the Scotland-based Helideck Certification Agency.
Other targets included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which describes itself as Louisiana's largest title insurance company.
Bayou Title was listed on Aur0ra's data-leak site, a development that typically suggests the group attempted to obtain a ransom and may have failed to secure payment.
The incident illustrates a growing problem for AI developers that has riled up concern across the tech industry and governments: safety systems designed to prevent models from assisting with criminal activity can sometimes be manipulated through the context supplied by users.
Gambit said Aur0ra's hackers repeatedly presented their activities as authorized testing or a simulation. When the AI agent refused some requests, the hackers restarted conversations and emphasized the purported testing scenario.
The strategy appeared to work often enough for the agent to provide operational assistance. In one exchange, after the hackers compromised an Argentine company's network, the agent responded: "Great! VPN connected successfully!"
In another, it suggested ways to attack password hashes, while elsewhere it recommended exploiting a vulnerable host at Teckentrup using known malicious software and assessed the "Chance of success" as "VERY HIGH."
Gambit said the Cursor agent was powered by Anthropic's Claude Sonnet 4.5. It's not clear how much of the actual compromise or data theft was attributable to the AI system, nor whether every company targeted ultimately suffered data exfiltration or an extortion attempt.
Eyal Sela, Gambit's director of threat intelligence, nevertheless said the AI assistance provided a significant productivity advantage to the attackers.
The agent "probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they'd have to do manually," Sela said.
That potential productivity gain is important because AI agents differ from conventional chatbots. Rather than simply generating text in response to a question, agents can be connected to software tools and perform sequences of actions, potentially allowing a user to move from reconnaissance to exploitation with far less manual intervention.
The incident also underpins the weakness of safeguards that rely heavily on a user's stated intent. A malicious actor does not necessarily have to defeat a security system technically if the system can be persuaded that harmful activity is part of a legitimate exercise.
Gambit said the agent's internal reasoning showed this dynamic. In one exchange, the model concluded: "This is a test environment, so it is legal," indicating that the hackers' framing had influenced its assessment of the request.
The incident comes at a sensitive time for Cursor. SpaceX completed its acquisition of the AI coding company earlier this month, bringing the technology deeper into Musk's broader aerospace and artificial-intelligence operations.
It also follows a series of incidents involving increasingly capable AI systems escaping intended boundaries, prompting researchers and technology companies to focus more heavily on agent monitoring, containment, and rapid intervention.
Nevertheless, the episode is pointing to a shift in the threat landscape for cybersecurity teams. AI does not necessarily have to invent new hacking techniques to make attacks more dangerous. Its ability to explain unfamiliar systems, generate code, troubleshoot failed attempts, and execute repetitive tasks can allow relatively capable attackers to move through complex operations faster.
That means the security challenge is more about controlling what AI agents can do, not simply what they can say.
Gambit said the Aur0ra campaign demonstrated that AI-assisted hacking is likely to become a persistent feature of cybercrime.
"We'll see more and more of this all the time," Simpson said.