Cursor AI hack

Russian-Speaking Hackers Used SpaceX's Cursor AI Tool to Breach Seven Companies

August 25, 2026Michael Hill

6 min read

Prefer TechResearch on Google

In Focus

  • A Russian-speaking ransomware affiliate used Cursor, SpaceX's AI coding assistant, to help breach at least seven companies
  • Victims span Belgium, Germany, Scotland, Argentina, Italy, and the US, identified through leaked chat logs
  • The chat logs, running April 8 to May 21, 2026, were exposed on a server the hackers left open
  • Cursor and SpaceX have not responded to requests for comment

A Russian-speaking affiliate of the Aur0ra ransomware operation used Cursor, the AI coding assistant owned by SpaceX, to help plan and execute intrusions into at least seven companies earlier this year, according to a report from security startup Gambit Security reviewed by Reuters. The case is one of the clearest documented examples yet of a commercial AI coding tool being used directly inside an active ransomware operation.

How did researchers uncover the campaign?

Gambit Security discovered the operation after finding a server that Aur0ra had inadvertently left exposed to the public internet. That server held Cursor chat logs spanning April 8 to May 21, 2026, giving researchers an unusually direct look at how the group used the AI tool during real intrusions rather than just in testing or planning.

Reuters was able to independently identify six of the affected organizations by reviewing portions of the chat data, which remained accessible online as recently as last month. Gambit's own report did not name the victims directly.

Which companies were affected?

The confirmed victims include Christeyns, a Ghent-based hygiene and cleaning products maker in Belgium, and Teckentrup, a German garage door manufacturer. Also affected was the Scotland-based Helideck Certification Agency, which certifies helicopter landing sites, along with an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, a Louisiana-based title insurance company. None of the six companies responded to Reuters' requests for comment.

How exactly was the AI tool used in the attacks?

Cursor is designed as a productivity tool for legitimate software development, built to help developers write and debug code faster through AI-assisted suggestions. In this case, the hackers repurposed that same capability to accelerate parts of the intrusion process itself. This mirrors a pattern security researchers have flagged elsewhere this year, including a separate campaign in which attackers used AI tools to help compromise hundreds of exposed firewall devices, part of a broader trend we've been tracking in our coverage of AI-enabled cyber threats across multi-cloud environments.

What does this mean for AI companies building coding tools?

Gambit's chief strategy officer, Curtis Simpson, said the case illustrates how AI providers are stuck in a cat-and-mouse game with malicious users actively trying to work around safety guardrails. That framing captures the core tension facing every company building general-purpose AI coding assistants: the same capabilities that make a tool useful for legitimate developers, fast code generation, debugging support, workflow automation, are equally useful to an attacker trying to move quickly through a network.

Cursor and its parent company, SpaceX, did not respond to Reuters' requests for comment on the findings.

What should enterprises take away from this?

This isn't an isolated incident. It fits into a pattern of ransomware and cybercrime groups increasingly incorporating commercial AI tools into their operational workflows, not to invent new attack techniques, but to execute known ones faster and with less manual effort. For security teams, that shifts part of the defensive conversation toward monitoring how AI tools are being used inside the network, not just what's being installed. We laid out a broader framework for addressing this shift in our guide to cybersecurity strategies for enterprises.

For the full report, see Reuters' original coverage.

Newsletters

See More

Get tomorrow's biggest tech conversations in your inbox today

No newsletter selected

Michael Hill - TechResearch

Michael Hill

Michael Hill is a tech enthusiast and writer based in New York City. He tracks the dynamic information technology environment and skillfully educates his audience about emerging tech innovations, trends and their impact on businesses.