Between 8 April and 21 May 2026, an affiliate of the Aur0ra ransomware group breached at least seven organisations across three continents, using the AI coding agent built into Cursor, the developer tool now owned by Elon Musk's SpaceX, to accelerate the work once the attacker was already inside. Confirmed victims include the Belgian hygiene products manufacturer Christeyns, the German garage door manufacturer Teckentrup, Scotland's Helideck Certification Agency, and Bayou Title in Louisiana, alongside an unnamed pharmaceutical distributor in Argentina and an unnamed manufacturer in Italy. The Israeli cybersecurity firm Gambit Security recovered twenty-eight chat sessions from an exposed command-and-control server and shared its findings with Reuters, which reported them on 27 August.
The attacker did not use Cursor's agent to gain initial access. In every case, the operator already held valid credentials or a foothold on the victim's network before opening the tool. From there, the agent was tasked with the hands-on work that normally consumes the most operator time: harvesting further credentials, escalating privileges, scanning the internal network for high-value targets, and configuring VPN access to maintain a persistent route back in.
The agent, running on Anthropic's Claude Sonnet 4.5 at the time, was not compliant by default. Gambit's chat logs show it refusing the operator's requests when they were framed plainly as an intrusion. The workaround required no exploit and no technical jailbreak: when refused, the operator simply closed the conversation, opened a new one, and reframed the same activity as an authorised penetration test. According to Gambit's threat intelligence director Eyal Sela, this worked almost every time, and the agent made the operator "30, 40, 50 percent faster" than working manually.
Seven confirmed breaches in six weeks is modest next to the mega-incidents this blog has covered this year, but the significance sits in the mechanism, not the record count. Four months earlier, on 1 May 2026, CISA, the NSA, and cyber authorities in Australia, Canada, New Zealand, and the United Kingdom had jointly published guidance on the careful adoption of agentic AI services, warning of twenty-three distinct risks across five categories and calling for AI agents to be treated as independent principals with their own cryptographically anchored identities and short-lived credentials. The Cloud Security Alliance now cites the Cursor case directly as validation of that warning. The episode has added to the troubles at Cursor's parent company, Anysphere, since its acquisition by SpaceX: OpenAI announced on 28 August that it would pull its models from Cursor by 12 November, citing distrust in SpaceX's willingness to honour contractual terms, a separate but concurrent blow.
The defence that failed here was not weak by conventional standards. It was, in fact, the defence much of the industry is currently building towards: a capable model with safety training, instructed to refuse participation in unauthorised intrusion, running inside a well-resourced developer tool. It refused. The problem was that the refusal lived entirely inside the model's own judgement, and that judgement could be relitigated in a fresh conversation with a different story attached. Nothing external to the model stood between "I won't do this" and "on reflection, I will."
Privilege escalation, credential harvesting at scale, and VPN reconfiguration are not routine developer actions. They are execution events, and GoFirm treats them that way regardless of whether the entity requesting them is a human contractor or an AI agent operating inside a coding tool. Before an agent can execute a privilege escalation, export credentials, or open a new persistent access route, GoFirm sends a real-time push notification to the named security authority accountable for that environment, on their own registered device, over a channel the agent has no path into. Nothing proceeds without a biometric confirmation on that device.
This does not depend on a model correctly judging whether a request is legitimate, and it does not degrade when the request is reframed, resubmitted, or dressed up as an authorised test. The confirmation request states plainly what is about to execute and on whose claimed authority. A story persuasive enough to change a language model's mind, however convincing, cannot produce a biometric confirmation on the named authority's own device over a separate channel. The execution boundary holds regardless of how credible the story told to the agent appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Gülen, K. 2026. AI agent in Cursor linked to ransomware breaches at 7 companies. Dataconomy, 31 August 2026.
2. Reuters. 2026. Russian-speaking hackers breached seven companies by tricking the AI agent in Cursor, the coding tool now owned by Elon Musk's SpaceX, into thinking the attacks were a test. Meduza, 27 August 2026.
Back to Blog
Case Studies·4 min read
Cursor's AI agent refused a ransomware operator once. Calling it a test reversed the answer, seven times over.
By GoFirm
