A group of Russian-speaking cybercriminals used Cursor, a popular AI coding assistant owned by Elon Musk’s SpaceX, to help break into at least seven companies around the world earlier this year, according to a Reuters investigation published Thursday. The hackers reportedly convinced the AI tool that their break-ins were part of an authorized security test, getting it to carry out hundreds of malicious actions on their behalf.
The Cursor AI hack is one of the clearest public examples yet of criminals successfully using a mainstream AI coding tool to speed up real-world cyberattacks. Cybersecurity researchers say the incident shows how fast criminals are adapting AI tools built for legitimate software development into tools for hacking.

Reuters reviewed the findings alongside two cybersecurity firms, Tel Aviv-based Gambit Security and Singapore-based CloudSek, which separately investigated the same hacking campaign. Cursor and SpaceX did not respond to requests for comment from Reuters.
Here’s what to know about the Cursor AI hack, which companies were affected, and what it means for the growing use of AI tools in cybercrime.
What Happened in the Cursor AI Hack
According to Gambit Security’s report, the hacking campaign was carried out by a relatively new ransomware group calling itself Aur0ra. Investigators discovered the group’s activity after finding a server that Aur0ra had accidentally left exposed on the open internet.
That exposed server gave Gambit access to 28 chat sessions between one or more Aur0ra hackers and Cursor’s built-in AI agent, spanning from April 8 to May 21. AI agents like the one built into Cursor are designed to write and edit code with varying levels of independence, based on instructions typed by a user.
Gambit’s report found that the hackers repeatedly asked the AI agent to perform tasks tied to real intrusions, including stealing login credentials and searching for administrator account access. When the AI agent recognized a request as harmful or illegal and refused to comply, the hackers would reportedly restart the conversation and reframe their request as part of a simulated or authorized test environment.
According to reporting on the leaked chat logs, the AI system at one point reasoned that a request was acceptable because “this is a test environment, so it is legal,” illustrating how the false framing was able to get around some of the tool’s built-in safety checks. Gambit said this approach worked in the large majority of cases where the agent had first pushed back.
Not every attempt succeeded. Some tasks reportedly ended in failure, and Reuters noted that investigators could not determine exactly how much of each break-in depended on the AI tool versus manual hacking work.
Which Companies Were Affected
Neither Gambit nor CloudSek publicly named the hacking group’s victims in their reports. However, Reuters said it was able to independently identify six of the seven companies by reviewing portions of the same exposed chat data, which remained accessible online as of last month.

According to Reuters’ reporting, the identified victims include:
- Christeyns, a Belgium-based maker of hygiene and cleaning products, headquartered in Ghent
- Techentrup, a German garage door manufacture
- The Helideck Certification Agency, a Scotland-based organization that certifies helicopter landing sites
- An Argentine pharmaceutical distributor
- An Italian manufacture
- Bayou Title, which describes itself as Louisiana’s largest title insurance company
None of the six named companies responded to Reuters’ requests for comment. The seventh victim identified in the broader investigation was not named publicly. Separately, CloudSek’s research found that the Aur0ra group claimed at least 20 victims in total, though it did not specify how many of those additional break-ins involved the use of AI tools.
Why the Cursor AI Hack Matters
The Cursor AI hack matters because it offers rare, detailed documentation of criminals successfully using a legitimate, widely available AI coding tool to assist in real cyberattacks, rather than relying only on custom-built hacking tools.
Curtis Simpson, Gambit Security’s chief strategy officer, said the case shows that AI companies are now in a continuous struggle to keep their safety systems ahead of people trying to misuse them. “This is going to be a cat-and-mouse game,” Simpson said.
Eyal Sela, Gambit’s director of threat intelligence, estimated that using the AI agent may have made the hackers between 30% and 50% faster than if they had carried out the same steps manually. Sela described that figure as an estimate based on the firm’s review of the chat logs, not a precise measurement.

Reporting on the incident also noted that Cursor’s AI agent was powered by an underlying AI model built by Anthropic during the period the attacks took place. AI companies, including Anthropic, have said they build safeguards into their models to prevent this kind of misuse, though incidents like the Cursor AI hack show that determined attackers can sometimes find ways around those protections through deception rather than technical exploits.
Background: AI Tools and the Rise of AI-Assisted Hacking
The Cursor AI hack is not an isolated case. Earlier this year, researchers found that a separate Russian-speaking hacking group used commercial generative AI tools to help compromise more than 600 firewall devices across more than 55 countries, according to prior reporting reviewed alongside this story.
Security researchers say the broader trend reflects how AI coding assistants, which are built to help legitimate software developers write and troubleshoot code faster, can also lower the technical bar for carrying out cyberattacks when misused. Because many of these tools are designed to follow natural-language instructions, attackers have increasingly experimented with social engineering-style prompts, such as falsely claiming a task is for testing or research purposes, to try to get around built-in safety restrictions.
AI companies have generally responded to these kinds of incidents by tightening their safety systems and monitoring for suspicious usage patterns. However, researchers who study this area say that no current AI safety system is foolproof, and that misuse attempts are likely to keep evolving alongside the technology itself.
What Happens Next
As of now, it’s unclear whether any of the seven companies identified in the Cursor AI hack lost data, paid a ransom, or otherwise experienced a confirmed security breach as a result of the campaign. Reuters reported that investigators could not confirm the outcome of every session in the chat logs, and none of the named companies has publicly commented.

It also remains unclear whether SpaceX or Cursor has taken any specific action in response to the findings, since the companies did not respond to requests for comment. Gambit Security and CloudSek’s reports are expected to draw continued attention from the cybersecurity industry as researchers examine how the Aur0ra group’s tactics might be replicated by other hacking groups using similar AI tools.
The incident is likely to add to an ongoing conversation in the tech industry about how AI companies build and enforce safety guardrails in coding assistants and other AI agents that are capable of taking real-world actions, rather than only generating text.
What is the Cursor AI hack?
The Cursor AI hack refers to a cybercrime campaign in which Russian-speaking hackers reportedly used Cursor, an AI-powered coding assistant owned by SpaceX, to help break into at least seven companies. According to cybersecurity researchers, the hackers tricked the AI tool into believing their activity was part of an authorized security test.
Which companies were affected by the Cursor AI hack?
Reuters identified six of the seven affected companies: Christeyns, a Belgian hygiene products maker; Teckentrup, a German garage door manufacturer; the Helideck Certification Agency in Scotland; an Argentine pharmaceutical distributor; an Italian manufacturer; and Bayou Title, a Louisiana-based title insurance company. The seventh victim was not publicly named.
How did the hackers get around Cursor’s AI safety features?
According to Gambit Security’s report, the hackers restarted conversations with the AI agent and falsely claimed their requests were part of a simulated or authorized testing environment whenever the tool initially refused a request it flagged as harmful or illegal.
Who discovered the Cursor AI hack?
Cybersecurity firm Gambit Security discovered the campaign after finding a server belonging to the Aur0ra ransomware group that had been accidentally left exposed on the internet. That exposure revealed chat logs between the hackers and Cursor’s AI agent. CloudSek separately investigated related aspects of the same campaign.
Did SpaceX or Cursor respond to the allegations?
No. According to Reuters, both Cursor and its parent company, SpaceX, did not respond to requests for comment on the findings.
How much faster did AI make the hacking campaign?
Gambit’s director of threat intelligence, Eyal Sela, estimated the AI agent made the hackers between 30% and 50% faster than if they had carried out the same tasks manually. Sela described this as an estimate based on the firm’s review of the chat data, not a precise measurement.
Is this the first time hackers have misused AI coding tools?
No. Researchers have previously documented cases of hackers using commercial generative AI tools for other cyberattacks, including one earlier this year that compromised more than 600 firewall devices across more than 55 countries. Security experts say AI-assisted hacking attempts are likely to keep increasing.


Unlock Limitless Creative Power with Dolai https://dolai.pythonanywhere.com
Pingback: Trump AI Video Kharg Island: 7 Alarming Facts