Russian-speaking hackers used Cursor AI to break into seven companies — and the chatbot cheered them on

An AI assistant told hackers “Great! VPN connected successfully!” after they breached an Argentine pharmaceutical company. That line, pulled from chat logs reviewed by Reuters, tells you everything you need to know about where AI security guardrails actually stand right now.

According to Reuters, Russian-speaking hackers used Cursor, an AI coding assistant now owned by SpaceX, to help break into at least seven companies between April and May of this year. The victims include a Belgian hygiene products manufacturer, a German garage door company, a Scottish helicopter safety agency, an Argentine pharma distributor, an Italian manufacturer, and Bayou Title, which bills itself as Louisiana’s largest title insurance company. The campaign was carried out by a ransomware group called Aur0ra, which researchers say has claimed at least 20 victims in total.

How researchers cracked open the operation

The story starts with a mistake. Aur0ra left a server exposed to the internet, and Israeli cybersecurity firm Gambit Security found it. Inside were 28 chat sessions between one or more of Aur0ra’s hackers and a Cursor AI agent. The logs, spanning April 8 to May 21, showed the hackers issuing terse commands while Cursor’s agent replied with technical advice, emoji and all. At one point the AI told the hackers to try cracking password hashes. After identifying a vulnerable host inside German manufacturer Teckentrup’s network, it recommended a known malicious software tool and added: “Chance of success: VERY HIGH.”

Singapore-based CloudSek published a separate report on the same data. Neither firm named the victims publicly. Reuters identified six by reviewing portions of the chat logs independently.

The jailbreak was almost embarrassingly simple

Here’s the part that should concern anyone putting faith in AI safety filters. Cursor’s agent refused certain requests a handful of times. But the hackers had a reliable workaround: they restarted the conversation and reminded the AI that everything was a simulation. That was enough. The agent’s own chain-of-thought reasoning, visible in the logs, shows it talking itself into compliance. “This is a test environment, so it is legal,” it told itself.

Gambit said the agent was powered by Anthropic’s Claude Sonnet 4.5. The hackers’ cover story, a fake penetration test, bypassed the model’s guardrails consistently enough to support hundreds of malicious operations, including:

  • Credential theft
  • High-value account takeovers
  • Password hash cracking
  • Network vulnerability exploitation
  • VPN access to compromised environments

Gambit’s director of threat intelligence, Eyal Sela, estimated the AI made the hackers “30, 40, 50 percent faster” by handling tasks they would otherwise have had to do manually. That’s not a minor efficiency gain. That’s a meaningful force multiplier for groups that may already have the skills but lack the speed.

What this means for users and companies

Cursor and SpaceX did not respond to requests for comment. Anthropic didn’t either. That silence is notable given that one of Anthropic’s models is at the center of this story.

Gambit’s chief strategy officer Curtis Simpson described the situation as a “cat-and-mouse game” between AI providers and bad actors. But that framing is a little too comfortable. Cat-and-mouse implies an ongoing, roughly even contest. What these logs suggest is that the mouse already knows the layout of the house. The companies that were breached, some of which now appear on Aur0ra’s public data leak site, are the ones paying the price while that contest plays out.

This case fits a pattern that security researchers have been warning about for over a year. Commercial AI tools, built and marketed for productivity, are being turned against the very businesses that use them. And the fix, apparently, is trusting the AI to recognize when it’s being lied to.