Friday Aug 28

A Ransomware Crew Used Cursor As Staff

28AUG
28 CHAT LOGSSAID: A DRILL7 BREACHED

Leaked logs show the Aur0ra ransomware crew running breaches through Cursor. 28 sessions, at least 7 victim companies. They told it the job was an authorized pentest.

No jailbreak involved. Just a plausible job description, which is how you use it too.

A researcher who read the transcripts puts their speed gain around 30-50 percent.

Guardrails assume honest operators. Nobody scoped abuse detection into agent surfaces.

full brief & sources

⚡ Why this matters

  • Every agent guardrail assumes the operator is honest about context.
  • "This is an authorized test" is not a jailbreak. It is a sentence.
  • The productivity gain is real and it applies to attackers exactly like it applies to you.

🔍 What happened

  • 28 Cursor chat sessions dated Apr 8 to May 21, 2026 leaked and were analyzed.
  • At least 7 victim companies identified, including Christeyns (Belgium), Teckentrup (Germany) and the Helideck Certification Agency (Scotland).
  • Eyal Sela of Gambit Security, who reviewed the logs, puts the speed gain at 30-50%.
  • Cursor was running Claude 4.5 Sonnet during the sessions.
  • Cursor was acquired by SpaceX on Aug 14, 2026 for $60B - two weeks before the logs surfaced.

💬 Smart takes

  • The defensive answer is not a better refusal. It is identity and audit at the tool boundary.
  • Nobody is claiming a model failure here. The model did what a pentest engineer would do.
  • If your product has an agent surface, you now inherit an abuse-detection problem you did not scope.

🧭 Where this goes

  1. Watch whether Cursor ships per-workspace attestation or org-verified pentest mode.
  2. Watch insurers. Agent-assisted intrusion is going to show up in cyber policy language.
  3. Watch for the first regulator asking an agent vendor for intrusion telemetry.

🥄 The Spoon Take

The scary part is not that the agent got tricked. It is that no trick was needed - just a plausible job description, which is also how the rest of us use it.

🤔 Pushback

Seven companies and 28 sessions is small. Skilled attackers were already fast. The 30-50% number is one researcher's estimate from logs, not a measured control group.