Cursor AI Hack Spurs Multinational Cybersecurity Investigation
A Russian-speaking cybercriminal group allegedly used the AI coding assistant Cursor to help breach at least seven companies, raising fresh concerns about how commercial AI tools can be misused in cybercrime.

A major cybersecurity investigation has revealed that a Russian-speaking hacking group allegedly used Cursor, an AI-powered coding assistant, to support attacks against at least seven companies in different countries. The findings were uncovered by cybersecurity firm Gambit Security and independently reviewed by Reuters. The targeted organizations reportedly included a Belgian chemical company, a German manufacturer and a U.S.-based business.
Investigators found evidence suggesting that the hackers used Cursor’s AI agent for hundreds of malicious operations during the campaign. According to the investigation, the attackers attempted to disguise their activity as legitimate security testing, prompting the AI system to assist with tasks connected to credential theft and network exploitation. The case demonstrates how AI tools designed for legitimate software development can potentially be manipulated for harmful purposes.
The incident has attracted international attention because it highlights a growing challenge for AI developers and cybersecurity agencies. Modern AI coding agents can automate complicated technical work, making them valuable for programmers but also creating new risks when criminals attempt to misuse them. The reported campaign shows that safeguards can face pressure from users who repeatedly reframe or disguise harmful requests.
The hackers reportedly belonged to a group identified as Aur0ra, and investigators discovered chat records connected to the alleged attacks. The investigation has intensified concerns about the rapid development of autonomous and semi-autonomous AI agents, particularly systems capable of interacting with software, networks and other digital tools with limited human intervention.
The case could have broader consequences for the AI industry. As AI companies build more capable coding assistants and autonomous agents, security experts are increasingly calling for stronger monitoring, improved safeguards and better systems for detecting misuse. The Cursor investigation serves as another warning that the same AI technologies transforming software development can also create serious cybersecurity risks when placed in the wrong hands.



