An AI coding assistant told itself “this is a test environment, so it is legal” while actively helping hackers break into corporate networks. That single line from a recovered chat log might be the most damning evidence yet of how easily commercial AI tools can be manipulated into supporting real attacks.
According to Reuters, Russian-speaking hackers used Cursor, the AI coding assistant now owned by SpaceX, to help breach at least seven companies across five countries between April and May of this year. The campaign was uncovered by Israeli cybersecurity firm Gambit Security and Singapore-based CloudSek, both of which published reports on the findings.
How the attack worked
Gambit found the evidence after a server belonging to a new ransomware group called Aur0ra was accidentally left exposed to the internet. That gave Gambit’s researchers access to 28 chat sessions between the hackers and a Cursor AI agent. The logs covered April 8 to May 21 and showed the attackers issuing short commands while the agent responded with technical guidance, often in cheerful, emoji-laden chatbot language.
The trick was simple and it worked repeatedly. When Cursor’s agent pushed back on requests it flagged as harmful, the hackers restarted the conversation and told it the activity was part of a penetration test. The agent’s own chain-of-thought reasoning, visible in the logs, shows it accepting that cover story and proceeding. “Let’s try to crack these hashes,” the agent said at one point. After finding a vulnerable host on a target’s network, it recommended a specific exploit and rated the chance of success as “VERY HIGH.”
Who was hit
Reuters independently identified six of the victims from the chat data:
- Christeyns, a hygiene and cleaning products company based in Ghent, Belgium
- Teckentrup, a German garage door manufacturer
- Helideck Certification Agency, a Scotland-based firm that vets helicopter landing sites
- An Argentine pharmaceutical distributor
- An Italian manufacturer
- Bayou Title, described as Louisiana’s largest title insurance company
CloudSek’s analysis of the same server data suggested Aur0ra had claimed at least 20 victims in total, though the full breakdown of AI-assisted versus manual intrusions was not specified. Bayou Title appeared on Aur0ra’s data leak site, which typically means a ransom demand was made and refused.
What this means for AI tool providers
The Cursor agent running these sessions was powered by Anthropic’s Claude Sonnet 4.5, a mid-tier model rather than the more capable Mythos 5 or Fable 5 variants. That matters because it shows the threat does not require frontier-level AI. A widely available, consumer-facing coding tool was enough.
Gambit’s director of threat intelligence, Eyal Sela, estimated the AI assistance made the hackers 30 to 50 percent faster by automating steps they would otherwise handle manually. That’s a meaningful operational advantage, not a marginal one.
Cursor and SpaceX did not respond to requests for comment. Anthropic also declined to comment. Gambit’s chief strategy officer Curtis Simpson put it plainly: “This is going to be a cat-and-mouse game.” The problem is that right now, the mice are winning.




