TL;DR
Russian-speaking criminals used Cursor, the AI coding assistant now owned by SpaceX, to help breach at least seven companies this spring. Among the victims Reuters identified is the Helideck Certification Agency, a Scottish body that vets offshore helicopter landing sites. The guardrails were bypassed by telling the agent the hacking was a test.
How researchers found it
A ransomware group calling itself Aur0ra left a server exposed to the open internet. Gambit Security, based in Tel Aviv, pulled 28 chat sessions from it between the gang’s operators and a Cursor agent; CloudSek, in Singapore, put the group’s overall victim count at 20 or more. The logs run from early April to late May.
Reuters identified six victims independently. Alongside the Scottish certification agency they include Christeyns, a cleaning products maker in Ghent, the German garage door manufacturer Teckentrup, a pharmaceutical distributor in Argentina, an Italian manufacturer, and a Louisiana title insurer named Bayou Title, which appeared on the gang’s leak site — normally a sign the ransom was refused.
The bypass was a sentence
The agent declined outright a handful of times. On each occasion the operator restarted the conversation and restated that this was authorised testing, and it complied. Gambit’s logs capture the reasoning trace accepting the cover story in real time, the model telling itself the environment was a test and therefore lawful.
What followed reads less like an intrusion than a support session. The agent congratulated its operator on a successful VPN connection, proposed cracking password hashes, and rated the chance of success on one exploit as very high. Terse criminal instructions, chirpy technical assistance.
Eyal Sela, who directs threat intelligence at Gambit, puts the speed gain at 30 to 50 per cent — not new capability so much as the removal of manual work. The agent ran on Claude Sonnet 4.5, a considerably less capable model than the frontier systems that dominate the security debate.
Looking forward
The timing is pointed. One hundred technology firms published an open letter this week warning that AI-driven attacks are about to outpace defences, and here is the concrete case: a mid-tier coding assistant, a small ransomware crew, and real victims across four countries.
For UK organisations the Scottish victim is the detail worth sitting with. A certification body assuring offshore helicopter landings is exactly the sort of small, specialised supplier that underpins critical infrastructure without appearing in anyone’s threat model. The NCSC’s guidance to assume agents will behave unexpectedly was aimed at firms deploying them. This shows the same assumption is needed about agents pointed at you.