Hackers deceive an AI agent to attack seven companies: who pays the damages

A group of Russian-speaking ransomware managed to bypass the safeguards of the Cursor programming agent by presenting its actions as authorized proofs. The case coincides with a new challenge for insurers: determining who is responsible when an AI causes damage using legitimate permissions.

5 minutes

fotonoticia 20260804110328 1920

fotonoticia 20260804110328 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

5 minutes

Most read

The artificial intelligence agents are already being used during real cyberattacks. Researchers from Gambit Security have documented how the ransomware group Aur0ra employed the programming agent Cursor to facilitate intrusions against at least seven companies, after getting the system to collaborate in malicious operations by presenting them as part of legitimate simulations.

The investigation, whose data has been reviewed by Reuters, allowed the identification among the victims of the Belgian hygiene products company Christeyns, the German manufacturer Teckentrup, the Scottish Helideck Certification Agency, and the American Bayou Title. An Argentine pharmaceutical distributor and an Italian manufacturer also appear. Reuters independently identified six of the companies from the analyzed records.

The hackers exposed 28 conversations with the AI

Gambit Security reached the campaign after locating a server that Aur0ra had accidentally left exposed on the internet. In it, they found 28 conversation sessions between the cybercriminals and one of the Cursor agents, corresponding to a period between April 8 and May 21.

The records show that the attackers used the system to receive assistance during different phases of the intrusions. The investigation documented operations related to credential theft and account takeover, in addition to the use of AI to generate scripts, develop tools, and produce or correct commands.

The agent rejected some requests that it identified as harmful or illegal. The attackers, however, managed to bypass those blocks by restarting the conversations and insisting that they were within a testing environment. The episode shows how a false context can be used to attempt to circumvent the security barriers of an AI agent.

The attacks were still directed by humans

The investigation does not demonstrate that Cursor autonomously decided to attack the companies. The recovered records show human operators giving instructions while the agent provided technical assistance during the operations.

Eyal Sela, director of threat intelligence at Gambit, estimated that the use of the agent likely allowed cybercriminals to work between 30% and 50% faster by automating tasks that would otherwise have to be developed manually. This is an estimate from the researcher and not an independent measurement.

Reuters also could not independently determine to what extent each intrusion was facilitated by Cursor nor establish that all breaches necessarily ended with stolen data or extortion attempts. Therefore, artificial intelligence cannot be attributed to the entire outcome of the attacks.

Cursor has been part of SpaceX since August

Cursor is a platform specialized in AI-assisted programming that has undergone a significant business change this month. SpaceX completed its acquisition in August 2026, an operation officially announced on the 14th.

The tool is designed to help developers work with code using artificial intelligence and has agents capable of executing different tasks. Precisely that capability makes these types of systems especially useful tools, but it also expands the potential consequences of malicious use.

Reuters requested comments from Cursor and SpaceX regarding Gambit's findings, but neither had responded at the time of publication of the investigation.

The problem for insurers: what happens if access was authorized

The case coincides with a question that is beginning to worry the insurance market. Traditional cyber risk policies are usually designed to respond to episodes such as ransomware, business interruptions, system recovery, or certain costs arising from an intrusion.

Autonomous agents introduce a different scenario. A company may voluntarily grant an AI access to certain applications, databases, or systems to perform its functions. If subsequently the agent performs a harmful action, the damage may occur using credentials and permissions that were originally legitimate.

This circumstance complicates the fitting of certain incidents into definitions conceived for conventional attacks. The question is no longer solely who managed to enter a network but includes what a tool can do once the organization itself has allowed it access.

Insurers begin to adapt their policies to AI agents

Reuters has consulted executives and analysts in the sector and confirms that insurers such as MSIG, QBE, and Beazley are reviewing how their policies respond to systems capable of progressively taking on tasks with greater autonomy.

This does not mean that incidents related to artificial intelligence will automatically be excluded from insurance. QBE believes that when the use of an AI ends up causing a conventional cyber incident covered by the contract, existing coverages may still apply. Beazley, for its part, is working on products and coverages adapted to the emergence of new risks.

The sector must also assess possible systemic events capable of generating simultaneous losses in numerous organizations. The spread of the same technology or provider among many companies can increase joint exposure to a failure or a shared vulnerability.

So, who pays for the damages caused by an AI agent?

There is no single answer. It will depend on how the incident occurs, the responsibilities of the parties involved, and especially the conditions established in each policy. A conventional attack carried out with the help of AI does not necessarily pose the same contractual problem as a harmful action executed by an agent through legitimately granted permissions.

One of the obstacles for insurers is the lack of historical experience. In the face of ransomware and other threats for which there are years of data, there is still little information on the frequency and cost of incidents directly caused by autonomous agents.

This uncertainty forces the sector to review definitions, limits, and exclusions as companies grant greater capabilities to these systems. The challenge is to determine how far coverage extends when the tool that causes the damage was authorized to operate within the organization.

From protecting passwords to controlling what an AI can do

The investigations known this Thursday show two dimensions of the same change. Cybercriminals are learning to incorporate commercial agents into their operations while companies deploy systems capable of interacting directly with networks, applications, and corporate data.

Security thus involves limiting not only who can access an infrastructure but also what permissions each agent receives and what actions they can execute. The greater their autonomy, the greater the impact of a manipulated instruction, a vulnerability, or unexpected behavior can be.

The case of Aur0ra demonstrates that the safeguards of these systems can become a direct target for attackers. The reaction of insurers anticipates the following question: how to distribute the economic consequences when the boundary between a legitimately authorized tool and a cybersecurity incident begins to blur.

Hola, soy Fren. ¿Cómo te ayudo?