Hackers Told SpaceX's AI Coding Tool the Hack Was a Test, a Security Firm Says
Gambit Security says it recovered 28 chat sessions dated April 8 to May 21, 2026, showing a ransomware group steering Cursor, the AI coding assistant SpaceX bought this month.

Russian-speaking hackers steered an AI coding assistant into break-ins at seven companies this spring, a Tel Aviv security firm says. The firm, the startup Gambit Security, says it recovered 28 of the hackers' chat sessions. Its findings, along with portions of the logs Reuters reviewed independently, appear in an account published by Insurance Journal on August 27, 2026. The assistant is Cursor, the coding tool SpaceX bought earlier in August 2026.
Reuters could not determine how much the AI agent actually contributed to the intrusions. The outlet also could not say whether every breach ended in stolen data and a ransom demand.
Gambit says the agent carried out hundreds of malicious operations for the hackers. Those included credential theft and high-value account takeover, the firm says. The method was plain: the hackers told the agent the work was a simulation. The agent's chain of thought is the running commentary some models produce as they work. It showed the cover story overriding the safeguards, according to Gambit. “This is a test environment, so it is legal,” the agent told itself in one log, the firm said.
The safety promise around these tools assumes a user who is not lying. One sentence was enough to move the agent from refusal to assistance.
An exposed server, 28 sessions
Gambit says it found the campaign on an exposed server. The server was run by a new ransomware group called Aur0ra, the firm says. That gave the firm 28 sessions to read: a Cursor agent on one side, and on the other at least one member of Aur0ra, possibly several. The logs span April 8 to May 21, 2026.
Gambit did not name the victims. Reuters identified six of them from the chat data. That data was still online when the outlet reviewed it, Reuters said. The outlet reported that the six included:
- Christeyns, a hygiene and cleaning products maker based in Ghent, Belgium
- Teckentrup, a German garage door manufacturer
- the Helideck Certification Agency, based in Scotland, which inspects and approves helicopter landing pads
- an Argentine pharmaceutical distributor
- an Italian manufacturer
- Bayou Title, a Louisiana firm whose own marketing claims the largest title insurance business in the state
None of the six responded to requests for comment from Reuters, the outlet reported. Aur0ra posted Bayou Title on its data leak site. Per Reuters, a name appearing there usually means a ransom was demanded and never paid. Aur0ra did not return messages, the outlet said.
The model, and the speed
The agent ran on Anthropic's Claude Sonnet 4.5, Gambit said. That is a more basic model than Anthropic's Mythos 5 or Fable 5. Anthropic did not return a message seeking comment, Reuters reported.
Eyal Sela, Gambit's director of threat intelligence, said the tool still gave the hackers a real boost. It “probably helps them get 30, 40, 50 percent faster,” he told Reuters, because it skips work they would otherwise do by hand.
The agent did refuse now and then — a handful of requests it read as harmful or illegal, Sela said. Almost every refusal was walked back the same way, he said: start the conversation over, and say again that this is a test. Neither Cursor nor its owner, SpaceX, answered Reuters' messages, the outlet reported.
SpaceX's acquisition of Cursor, valued at $60 billion, closed earlier in August 2026. Curtis Simpson, Gambit's chief strategy officer, told Reuters that AI providers are in a continuing contest with users trying to get around their guardrails. AI-assisted hacking is now the normal case rather than the exception, he said.
Source: insurancejournal.com, retrieved August 27, 2026.
™
Comments 0