Hackers Used SpaceX's Cursor AI Tool to Breach Seven Companies, Researchers Find
A Russian-speaking ransomware affiliate spent weeks coaxing Cursor's AI coding agent into helping breach manufacturers, insurers and a pharmaceutical distributor across nine countries, according to two security firms whose findings were independently reviewed by Reuters.
A Russian-speaking hacking affiliate spent weeks this spring coaxing Cursor, the popular artificial-intelligence coding assistant now owned by SpaceX, into helping it break into corporate networks across nine countries, according to two independent cybersecurity firms whose findings were separately reviewed by Reuters.
The Tel Aviv-based security startup Gambit Security said in a report published Thursday that it discovered the campaign after finding a server that the hacking affiliate had carelessly left exposed to the open internet. The server held 28 logged conversations between the intruder and Cursor's AI coding agent, running from April 8 to May 21, alongside stolen credentials, intrusion tools and a working copy of the group's ransomware encryptor. The affiliate has been linked to a newly identified ransomware operation calling itself Aur0ra.
In the recovered chat transcripts, the hacker typed terse instructions in Russian and Cursor's agent answered with detailed, upbeat technical guidance, including a recommendation to use a well-known exploitation tool after the attacker described finding a vulnerable host inside a victim's network. When the AI system's safety filters intervened, the attacker got around them by simply restarting the conversation and claiming to be running an authorized penetration test, according to the chat logs.
The find is one of the clearest documented examples yet of an AI coding agent being used step by step across an entire intrusion, rather than for an isolated task such as drafting a phishing email or debugging a single script. Researchers who reviewed the logs said the hacker appeared to treat Cursor less like a tool and more like a junior teammate, asking it to interpret scan results, choose which credentials to try next, and explain unfamiliar error messages, then folding the AI agent's answers directly into the next command typed against a live victim network.
The numbers
Gambit tied the Cursor-assisted intrusions to at least seven organizations: Christeyns, a Belgian maker of hygiene and cleaning products; Teckentrup, a German garage-door manufacturer; the Helideck Certification Agency in Scotland; an Argentine pharmaceutical distributor; an Italian manufacturer; Bayou Title, a Louisiana-based title-insurance firm; and an unnamed Belgian chemical company, according to an account of the Reuters investigation carried by Insurance Journal.
A wider, separate analysis of the same exposed server by the Indian threat-intelligence firm CloudSEK put the total considerably higher. CloudSEK's own investigation counted more than 20 organizations targeted across nine countries between April and July, with the operator obtaining domain-administrator or other interactive access at 17 of them. Four victims eventually appeared on Aur0ra's dark-web leak site. Manufacturing, food and agriculture, and professional-services firms made up much of the target list. The server also exposed the group's finances: roughly seven bitcoin held in a linked wallet, evidence of at least two ransom payments, and revenue-sharing arrangements between affiliate and operator that ran as high as a 79-21 split, with a portion of the proceeds moved through a layered "peeling chain" of cryptocurrency transactions that researchers said was designed to obscure the money's ultimate destination.
CloudSEK also found evidence of just how deep the affiliate's access ran in some of the compromised networks: backup-system credentials, hashed Azure Active Directory Connect account data, Kerberos ticket-granting material, and enumeration of SAP and other enterprise resource-planning systems. That combination, researchers said, would typically let an attacker not only encrypt a victim's live systems but also disable or corrupt the backups an organization would otherwise use to recover without paying.
How the intrusions worked
Aur0ra's ransomware was written in Zig, an unusual choice of programming language for the genre, with separate builds for Windows — disguised under the filename sap.exe — and for Linux and VMware ESXi servers, researchers who examined the exposed infrastructure found. The ESXi variant forcibly shut down running virtual machines before encrypting their files and rewrote the login banner on compromised hosts to display the ransom demand. To move through victim networks once inside, the affiliate leaned on well-documented Windows weaknesses — Kerberoasting, so-called AS-REP roasting, and abuse of Active Directory's certificate-issuing services — the same categories of techniques Cursor's agent is recorded helping the hacker work through in the chat logs.
The episode is not the first time a commercial AI coding tool has surfaced inside a criminal intrusion, though it is among the most fully documented. A year earlier, Anthropic — whose Claude models power part of Cursor's underlying agent — disclosed that a hacker had used its own Claude Code tool to automate an extortion campaign against 17 organizations, drafting malware and ransom notes with little manual coding assistance of its own. Security researchers began calling the pattern "vibe hacking," describing criminals with limited technical skill who lean on an AI system's own judgment to fill the gaps that used to require years of hands-on experience. What distinguishes the Aur0ra case, researchers said, is the breadth of the intrusion lifecycle the AI agent appears to have touched — not just malware development but live reconnaissance, credential abuse and lateral movement inside networks that belonged to real, operating companies.
Cursor itself became part of a much larger corporate story in June, when SpaceX completed a record $60 billion all-stock acquisition of Cursor's parent company, Anysphere, folding the coding assistant into Elon Musk's growing artificial-intelligence ambitions and instantly making it one of the most widely deployed AI agents in professional software development. That scale is precisely what worries researchers: a tool built to be trusted with broad access to a legitimate developer's codebase and infrastructure carries much of that same reach when a criminal manages to convince it that the account holder's intentions are legitimate.
The victims identified so far skew toward mid-sized manufacturers, distributors and service firms — the kind of organizations that often run lean security teams and lack round-the-clock monitoring, making them comparatively easy targets for an attacker leaning on AI assistance to compensate for its own technical gaps. A hygiene-products maker, a garage-door manufacturer, a helicopter-deck safety certifier and a title-insurance firm have little in common except that none appears to have had the security staffing to detect an intrusion unfolding gradually over days or weeks. None of the companies named in the reporting has issued a public statement on the intrusions, and it is not clear how many, beyond the four that appeared on Aur0ra's leak site, ultimately had data stolen or systems encrypted.
Reaction and what happens next
Researchers described the incident as evidence of an escalating contest between AI developers building in safeguards and criminals working just as quickly to route around them.
"This is going to be a cat-and-mouse game," said Curtis Simpson of Gambit Security, describing the widening use of commercial AI tools by cybercriminals.
Cursor and its parent, SpaceX, did not respond to requests for comment on the findings, nor did Anthropic, according to the reporting reviewed by Reuters. Cursor's own published security commitments point to third-party penetration testing, ISO certification and data-handling safeguards, but make no specific mention of how the company polices misuse of its AI agent by paying customers who claim legitimate intent.
Neither Gambit nor CloudSEK has said whether law enforcement has been notified or whether any arrests are expected. Other outlets that reviewed the same material reported that researchers expect the Aur0ra affiliate, or others copying its methods, to keep experimenting with AI-assisted intrusions now that the approach has proven workable against real targets, since much of what made the campaign effective — patient reconnaissance, methodical credential harvesting, careful selection of which systems to encrypt first — required no special access to Cursor beyond an ordinary paid account.
For now, both security firms are urging the companies still exposed, and others in similar industries, to treat ransomware as a slow-building intrusion rather than a single moment of encryption, given that the recovered logs show attackers spending weeks inside networks before deploying their final payload. Recommended defenses echo familiar advice — multifactor authentication on administrative accounts, rapid patching of internet-facing systems, and offline or immutable backups — but researchers said the AI component adds a new wrinkle: security teams now have to assume that a competent-sounding technical plan moving through their network may have been drafted not by a skilled human operator but by a chatbot coaching an otherwise inexperienced one. Whether AI vendors can build safeguards that catch that distinction reliably, without also blocking the legitimate penetration testers and security researchers who rely on the same tools, remains, in Simpson's words, an open and escalating contest.
CISA Orders Federal Agencies to Patch Critical Gitea Flaw Under Active Attack

OpenAI's first custom chip claims to outperform Nvidia's Blackwell on inference
