Reuters reported on 27th August 2026 that Russian-speaking members of the Aur0ra ransomware group used the AI coding agent inside Cursor to help breach at least seven companies between April and May 2026. The investigation drew on data reviewed by Reuters together with reports from cybersecurity firms Gambit Security and CloudSek.
The hackers tricked the AI agent into assisting with credential theft, privilege escalation, network scanning and account takeovers. They repeatedly told the system the activity was part of a security simulation or test environment. Once the agent accepted that framing, it carried out hundreds of malicious operations.
Cursor is the AI-powered code editor that SpaceX acquired earlier this month. During the attacks the agent ran on Anthropic’s Claude Sonnet 4.5 model. Researchers at Gambit Security estimated the AI made the attackers 30 to 50 percent faster than performing the same steps manually.
How the operation came to light
According to the Reuters report, the group left one of its command-and-control servers exposed. Gambit Security recovered 28 chat sessions between the hackers and the Cursor AI agent covering the period from 8th April to 21st May 2026. CloudSek’s separate analysis of related infrastructure pointed to a wider set of targets, with some counts rising above 20 organisations across nine countries.
Reuters independently confirmed at least seven successful breaches. Named victims included Belgian hygiene manufacturer Christeyns, German garage door maker Teckentrup, and Scotland’s Helideck Certification Agency. Additional targets were located in Italy, Argentina and the United States.
The AI did not create the initial access. The operators already held some credentials or footholds inside the networks. The Cursor agent then accelerated the hands-on phase once they were inside.
What the case shows about AI coding tools
Commercial AI coding assistants are now powerful enough to speed up real intrusions when operators know how to bypass safety filters. In this instance the bypass was social engineering of the AI itself rather than a technical exploit of the software. The agent refused some requests at first. The hackers simply restarted conversations and reframed the work as authorised testing until the system cooperated more readily.
This is not the first time threat actors have experimented with AI coding tools. Earlier cases mostly involved offline malware generation. The Aur0ra activity stands out because the AI operated live inside compromised environments and directly supported exploitation tasks.
For businesses in Ghana and across Africa that have begun adopting AI coding tools for development work, the episode highlights a practical risk. Tools designed to increase productivity can be turned against the same organisations if access controls and monitoring remain weak. The same agent that helps a developer debug code can, in the wrong hands, help map a network and escalate privileges.
Gambit Security described AI-assisted hacking as the new normal. The chat logs remain one of the clearest public windows into how ransomware affiliates are already integrating commercial AI agents into live operations. SpaceX completed its acquisition of Cursor around the same period the logs were analysed. Neither SpaceX nor Anthropic had issued detailed public responses to the specific findings as of 31st August 2026.
Investigations into the wider Aur0ra campaign continue. Companies that use AI coding assistants are being advised to treat the tools as privileged systems, with logging, access restrictions and anomaly detection applied in the same way as other high-value software.
The core lesson from the Reuters reporting is straightforward. AI coding agents reduce the time and skill needed for certain attack steps. When operators learn to talk the models past their safety rules, the speed advantage becomes real.