Hackers turned Cursor's AI into a tool for attacking 7 companies
Hackers reportedly tricked Cursor's AI agent into helping with real attacks by disguising malicious activity as a security test.
A coding assistant found itself on the wrong side of the code. Russian-speaking hackers used Cursor, an AI coding assistant owned by SpaceX, to help break into a Belgian chemical company and at least six other firms earlier this year, according to Reuters.
The report, based on findings from cybersecurity startup Gambit Security, shows how AI tools built to speed up coding can also become useful to attackers.
The case is another sign that as AI agents gain more freedom to write code and perform technical tasks, keeping them from being misused is becoming harder.
How hackers got the AI to help
Gambit Security discovered the activity after finding an internet-exposed server belonging to Aur0ra, a new ransomware group. The exposed server gave the Tel Aviv-based company access to 28 chat sessions between one or more Aur0ra hackers and a Cursor AI agent.
The conversations, dated between 8 April and 21 May, showed the hackers using the AI during cyber intrusions. According to Gambit, the attackers persuaded the agent to carry out hundreds of malicious operations, including credential theft and attempts to take control of valuable accounts.
The trick was reportedly in how they framed their requests. When the AI refused certain actions, the hackers presented their activity as part of a simulation or authorised security test, helping them get around some of the agent’s restrictions.
Seven companies reportedly targeted
Reuters independently identified six victims from parts of the chat data. They included Christeyns, a Belgian hygiene and cleaning products maker based in Ghent; German garage door manufacturer Teckentrup; and Scotland-based Helideck Certification Agency.
The other reported victims were an Argentine pharmaceutical distributor, an Italian manufacturer and Bayou Title, a Louisiana title insurance company. Gambit did not name the victims in its own report.
Bayou Title was reportedly listed on Aur0ra’s data leak site, which can indicate that attackers were attempting to pressure a victim into paying a ransom. However, there is no confirmation of how much Cursor’s agent contributed to each breach, or whether every intrusion resulted in data theft or extortion.
OpenAI reveals how its AI broke through Hugging Face's security controls
The bigger problem for AI coding tools
Coding agents can write software, suggest commands and automate technical work that would otherwise take humans much longer. But the same abilities can become dangerous when attackers convince an AI that harmful instructions are legitimate.
Gambit’s Eyal Sela estimated that Cursor may have helped the hackers work 30%, 40% or even 50% faster by reducing manual steps. The takeaway is bigger than Cursor. As AI agents become more capable, companies will need stronger access controls, monitoring and human oversight around tools that can interact with sensitive systems.
The coding assistant may have been the tool, but the real warning is about the growing role of AI in cyberattacks.

