Technology

Russian Hackers Utilize SpaceX AI Tool to Breach Seven European Companies

r
rafidayn24 Aug 28, 2026
2 min read
Share:
Russian Hackers Utilize SpaceX AI Tool to Breach Seven European Companies

Cybersecurity firm Gambit Security has revealed that Russian-speaking hackers utilized the Cursor platform, an AI-powered programming assistant from SpaceX, to breach a Belgian chemical company and at least six other firms earlier this year. This wave of cyberattacks, executed with the aid of artificial intelligence, represents the latest instance of malicious actors exploiting commercially available AI tools to carry out sophisticated intrusions. Curtis Simpson, Gambit's Chief Strategy Officer, explained that this development also highlights how AI service providers are engaged in an endless arms race with malicious users attempting to circumvent protective measures. Simpson added, "This will be a cat-and-mouse game." Neither Cursor nor its parent company SpaceX responded to requests for comment on these reports. Gambit stated that it uncovered the hacking campaign after inadvertently discovering an online server belonging to a new ransomware gang known as Aurora. This allowed the Tel Aviv-based company to review 28 chat sessions between one or more Aurora hackers and a Cursor AI agent, which are autonomous software programs with varying degrees of independence. In its report, Gambit indicated that Aurora persuaded the AI model to perform hundreds of malicious operations, such as stealing credentials or taking over high-value accounts, by falsely claiming the breach was part of a simulation exercise. Gambit quoted the hackers saying in one instance: "We need any user account with full settings privileges," and in another: "Find any valid passwords." Gambit did not directly identify the entities subjected to these cyberattacks, but an independent review of parts of the chat data, which remained accessible online until last month, revealed six of the victims. Chat logs, spanning from April 8 to May 21, showed that among the victims of the Aurora-led breach, supported by Cursor, were Kristens, a Belgian hygiene and disinfectant product manufacturer based in Ghent; Teckentrup, a German garage door manufacturer; and Hlidek, a Scottish agency responsible for inspecting helicopter landing sites. None of the mentioned companies responded to requests for comment. Aurora, a hacking and cyber-infiltration group that began launching online attacks this year, also did not respond to any messages.