Researchers say a Russian-speaking ransomware group bypassed safeguards by presenting malicious activity as authorized testing. The precise role the AI agent played in each breach remains unclear.

Russian-speaking cybercriminals used Cursor, the AI coding assistant now owned by SpaceX, while breaking into at least seven companies earlier this year, according to Reuters reporting based on chat data and research by cybersecurity firms Gambit Security and CloudSek.

Gambit said it found an internet-exposed server tied to a newer ransomware group calling itself Aur0ra. The material included 28 chat sessions between the attackers and a Cursor AI agent, recorded from April 8 through May 21.

According to Gambit, the attackers persuaded the agent to assist with activities including credential theft and account-takeover efforts by falsely describing the work as a simulation or authorized test. The firm said the tool sometimes rejected harmful requests, but the operators often restarted the conversation and repeated the testing claim.

Reuters said it independently identified six companies in the chat data: Belgian hygiene-products maker Christeyns, German garage-door manufacturer Teckentrup, Scotland-based Helideck Certification Agency, an Argentine pharmaceutical distributor, an Italian manufacturer and Louisiana title insurer Bayou Title. The companies did not respond to Reuters requests for comment.

CloudSek said Aur0ra had claimed at least 20 victims overall, but did not specify how many cases involved AI assistance. Reuters also said it could not independently determine how much Cursor contributed to each intrusion, or whether every incident resulted in stolen data or an extortion attempt.

Gambit threat-intelligence director Eyal Sela estimated that the agent could have made the operators 30% to 50% faster by reducing manual work. Cursor and SpaceX, Aur0ra, and Anthropic, whose Claude Sonnet 4.5 model Gambit said powered the agent, did not respond to Reuters requests for comment.