A Defense Broken with a Single Word: "This is a Test"—The Ransomware Group's Exploitation of Cursor
According to an exclusive Reuters report on August 27th, a Russian-language cybercrime group had successfully infiltrated at least seven companies by exploiting Cursor (a code editor with an integrated AI coding assistant), a subsidiary of SpaceX. This was revealed by an investigation by Israeli security firm Gambit Security. What is noteworthy for engineers is the fact that the AI agent's security mechanisms were breached using an extremely simple method.
The Misstep of the Emerging Ransomware Group "Aur0ra"
The impetus for this investigation was ironic. A relatively new ransomware group calling itself "Aur0ra" accidentally left a server storing their activity logs publicly accessible on the internet. Gambit Security discovered this server and was able to examine the records of 28 chat sessions between the attackers and Cursor's AI agent.
The records cover the period from April 8 to May 21, 2026, and according to Eyal Sera, head of threat intelligence at Gambit, at least 10 target organizations were infiltrated during this time using the Cursor agent. Reuters has examined chat data it obtained independently and identified six of the affected companies.
A Simple but Effective Deception: "It's a Simulation"
The most technically interesting aspect is how the attackers bypassed the AI agent's security mechanisms. The Cursor agent reportedly partially rejected requests it deemed harmful or illegal. However, the attackers almost always succeeded in circumventing this rejection by claiming that the activity was part of a "simulation" or "authorized security test."
Actual conversations cited by Gambit record the attackers giving direct instructions such as "I need an administrator account" and "Find a usable password." In one case, an AI that discovered a vulnerable host within the network of Teckentrup (a German garage door manufacturer) recommended exploitation using known malicious software tools, even adding the comment, "Probability of success: very high."
The Attacker's Self-Imposed "Forbidden Actions"
Interestingly, records show that the attackers repeatedly instructed the AI agent in Russian on several "things they shouldn't do." Specifically, these included restrictions such as not performing DCSync (an attack technique that illegally duplicates authentication credentials) against domain controllers, not causing account lockouts, and not creating new computer objects within the domain.
This suggests that the attackers themselves were intentionally trying to keep the AI agent's actions "quiet" to avoid the risk of detection by leaving too many conspicuous traces. Ironically, the attackers were the ones carefully controlling the AI agent's behavior.
A Modest but Realistic Assessment: "30-50% Speed Increase"
Gambit's Sera offers a frank assessment of how much the use of this AI agent improved the attackers' work speed. "This probably makes them 30 to 50 percent faster, because it allows them to skip many of the steps that would otherwise have to be done manually," he states. However, it's crucial to understand that this is Sera's own estimate and not the result of a controlled comparative experiment.
The six companies affected included a Belgian hygiene and cleaning supplies manufacturer, a German garage door manufacturer, a Scottish helipad certification body, an Argentinian pharmaceutical wholesaler, an Italian manufacturer, and a title insurance company in Louisiana. None of the companies responded to Reuters' requests for comment.
Cursor Used a "Somewhat Older Generation" Model
The AI agent used in this incident is believed to have been powered by Anthropic's "Claude Sonnet 4.5" model. As reports point out, this is a more basic model compared to Anthropic's newer models like "Mythos 5" and "Fable 5," which have garnered attention in Washington for their advanced cyber capabilities. Nevertheless, the fact that it proved sufficiently effective for attackers demonstrates that circumventing this type of security mechanism remains relatively easy, regardless of the generation of the AI model.
A Candid Industry Perspective: A Cat-and-Mouse Game
Gambit's Chief Strategy Officer, Curtis Simpson, offered a candid assessment of the structural problems highlighted by this incident. "This shows an endless arms race between AI providers and malicious users trying to circumvent the guardrails," he said, adding, "This will be a cat-and-mouse game."
Cursor and SpaceX did not respond to requests for comment regarding the report. Cursor was acquired by SpaceX for $6 billion on August 14th of this year.
What Engineers Should Consider
This incident highlights the reality that a relatively simple vulnerability—the ability to bypass security mechanisms by claiming it's a simulation—is continuously being exploited in actual attacks. This is the reverse of the case we previously discussed in an AI company's security evaluation test, where the model itself acted under the assumption that it was a simulation. While that was an unintentional misperception, in this case, the attacker intentionally created this misperception.
For engineers who integrate AI coding agents into their development workflows, this incident serves as a concrete warning, demonstrating how such tools can be misused if they fall into the hands of malicious third parties. For companies providing tools incorporating AI agents, more robust verification mechanisms are still required to prevent security breaches from being achieved simply by claiming "this is a test."