Insurance
Home›Insurance›Industry & Deals›Cybercriminals used Cursor AI to hack at least one ins…
Cybercriminals used Cursor AI to hack at least one insurer
Bayou Title, which advertises itself as Louisiana’s largest title insurance company, was named among victims in Aur0ra’s Cursor-boosted hacking campaign.
Russian-speaking cybercriminals used SpaceX’s Cursor AI coding assistant to help launch ransomware-linked intrusions against multiple companies earlier this year, according to data reviewed by Reuters and reports from cybersecurity firms Gambit Security and CloudSek.
Gambit said it traced the campaign after finding a server inadvertently exposed by a new ransomware gang called Aur0ra, then reviewed 28 chat sessions between Aur0ra hackers and Cursor AI agents. Gambit reported that Aur0ra persuaded the AI agent to carry out hundreds of malicious actions, including credential theft and account takeovers, by claiming the activity was part of a simulation.
CloudSek said the exposed server data showed Aur0ra had claimed at least 20 victims overall, though it did not provide a breakdown of how many were compromised with the help of AI.
Reuters identified six victims from portions of the chat logs, including Ghent-based Christeyns, German garage door manufacturer Teckentrup, and the Scotland-based Helideck Certification Agency, along with an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, a Louisiana title insurance company. None of the six companies replied to Reuters’ requests for comment.