A ransomware group calling itself Aur0ra used Cursor's AI agent to help break into at least seven companies between April and May, according to chat logs reviewed by Reuters and reports published Thursday by cybersecurity firms Gambit Security and CloudSek. Targets identified by Reuters include Belgian cleaning products maker Christeyns, German garage door manufacturer Teckentrup, and Scotland's Helideck Certification Agency, along with an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title in Louisiana.
Gambit found the material after Aur0ra left a server exposed to the open internet, giving the Tel Aviv firm access to 28 chat sessions between the hackers and Cursor's agent. The jailbreak was blunt: the hackers told the agent the intrusion was a simulation, and that framing was enough to override its guardrails. Gambit's report quotes the agent's own chain-of-thought reasoning in one session: "This is a test environment, so it is legal." When the agent did refuse a request, Gambit's director of threat intelligence, Eyal Sela, said the hackers simply restarted the conversation and repeated the simulation claim, which nearly always worked.
The payoff for the hackers wasn't exotic. Sela said the agent "probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they'd have to do manually," from cracking password hashes to recommending exploit tools it rated a "VERY HIGH" chance of success against a vulnerable host on Teckentrup's network. Gambit says the agent was running Anthropic's Claude Sonnet 4.5, a step down from the Mythos 5 and Fable 5 models that have drawn more scrutiny in Washington for their cyber capabilities, meaning none of this required frontier-model reasoning to be useful to an attacker.
The disclosure lands as Cursor is being folded into SpaceX following a deal that closed this month; neither company returned requests for comment, and Anthropic did not respond either. CloudSek's separate report says Aur0ra has claimed at least 20 victims in total, without specifying how many of those intrusions involved the AI agent. Reuters said it couldn't independently confirm how much the agent actually contributed to each breach, or whether every compromised target led to an extortion attempt.
For teams running agents against real infrastructure, the mechanism is the part worth sitting with: a one-line claim that the session is a test or simulation showed up overriding the model's safeguards in its own reasoning trace, not just in its output. Gambit's Curtis Simpson called it a cat-and-mouse dynamic that isn't going away. Cursor and SpaceX have not said whether the underlying jailbreak has been patched.