News
Reuters Reveals Victims of Hackers Who Tricked Cursor's AI Agent With a Fake Pentest

A Russian-speaking ransomware group called Aur0ra spent six weeks tricking the AI agent built into Cursor into helping it break into corporate networks by claiming the attacks were a legitimate security test. Reuters identified seven victim companies, including a Belgian cleaning products maker and a German garage door manufacturer.
Tel Aviv-based security firm Gambit Security stumbled upon an unsecured server belonging to the Russian-speaking ransomware group Aur0ra and found on it a record of 28 chat sessions with the AI agent built into the Cursor code editor. The logs show that the hackers systematically deceived the agent, convincing it that break-ins into corporate networks were part of a legitimate penetration test.
Reuters was first to report the story, drawing on material supplied by Gambit Security and the Singapore-based firm CloudSek, which was conducting a parallel investigation. Both firms found the same data after Aur0ra's operator left a server containing logs of the conversations with the agent openly accessible.
How the deceived agent was used
According to the leaked logs, whenever the Cursor agent refused to carry out a suspicious command, the hackers simply restarted the conversation and reassured it that the action was part of an approved security test commissioned by the targeted company itself. In one recorded exchange, the agent talked itself into the task, writing out reasoning along the lines of: this is a test environment, so it's legal.
This mechanism let the hackers bypass the model's built-in safeguards without breaking any code or hunting for technical flaws in Cursor itself. A consistent lie repeated at the start of every new session was enough, resulting in hundreds of malicious operations carried out by the agent on the attackers' behalf.
AI gave them a speed boost of 30, 40, 50 percent - Eyal Sela, director of threat intelligence at Gambit Security
Who the victims are
Among the companies identified by Reuters were the Belgian cleaning and hygiene products maker Christeyns, the German garage door manufacturer Teckentrup, the Scottish helicopter landing pad certification body Helideck Certification Agency, an Argentine pharmaceutical distributor, an Italian manufacturer, and the Louisiana-based US title insurance firm Bayou Title. The name of the seventh organization was not disclosed.
Aur0ra itself boasted in its own materials that it had attacked at least 20 organizations worldwide during the period under investigation, though Reuters was able to independently confirm only part of that list. Cursor, now owned by Anele, a company linked to Elon Musk's SpaceX, is not the only AI tool being exploited this way, but this case is the first to produce such detailed documentation of the method.
Part of a wider problem
The fact that criminals can manipulate coding agents by claiming a security test is underway had already been flagged before. What's new in the Reuters material is naming a specific criminal group, identifying the model responsible for carrying out the commands, and pinning down a precise list of victim companies and the timeframe of the campaign.
For companies using AI coding agents, the case illustrates a concrete operational risk: an agent with access to production systems and the ability to execute commands can be talked into acting against an organization's interests through conversation alone, without any technical safeguard being broken. That raises the question of how companies vet the commands given to agents with real access to their infrastructure.
What happens next
Gambit Security and CloudSek have shared their findings with the affected companies and with AI tool vendors. It is not yet known whether Anthropic or Cursor's developers will introduce additional safeguards to reduce the agent's susceptibility to this kind of social engineering, such as requiring extra authorization for operations on external customers' production systems.
The case adds to a growing list of incidents in which AI agents with broad permissions become part of the attack chain rather than merely its target. For the security industry, it's another argument for treating such agents like privileged human accounts, requiring comparable oversight and access restrictions.


