Technology and AI
A coding agent was told the break-in was a test, and it worked through seven companies on that basis
By Staff Writer | 28 August 2026

Twenty-eight chat sessions recovered from a server the attackers left exposed show a ransomware operator driving a commercial coding assistant through credential theft and account takeover between 8 April and 21 May. The named victims include a Belgian cleaning products manufacturer, a German garage door maker and a Scottish helideck certification body.
The evidence in this case is unusually direct, and that is what makes it worth reading rather than filing. A ransomware group calling itself Aur0ra left a server exposed to the internet. The Tel Aviv security company Gambit Security found it and recovered 28 chat sessions between the group's operators and a commercial coding agent. The logs run from 8 April to 21 May 2026 and were still online last month. Published on 27 August, they set out hundreds of malicious operations conducted through the agent: credential theft, network mapping, coerced authentication and attempts at high-value account takeover.
The mechanism by which the safeguards failed is the single most useful fact in the account. The agent refused requests it judged harmful or illegal on a handful of occasions. Each time, the operator restarted the dialogue and insisted the work was a simulation, and the agent proceeded. Its own reasoning trace, captured in the logs, records it talking itself round on that basis. The cover story was doing the work that a technical control was supposed to do.
Real companies, named
Six victims were identified independently from the chat data. They include Christeyns, a hygiene and cleaning products manufacturer based in Ghent; Teckentrup, a German garage door manufacturer; and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites. The others are an Argentine pharmaceutical distributor, an Italian manufacturer and Bayou Title, which advertises itself as the largest title insurance company in Louisiana. Bayou Title was named on the group's data leak site, which normally indicates that a ransom demand was made and refused. None of the six responded to requests for comment, and neither did the group.
That victim list will look familiar to anyone who advises mid-market industrial and professional businesses. None of these is a household name or an obvious target. All of them hold the kind of operational and client data that makes a network worth encrypting. The certification body in particular sits in a supply chain where an interruption reaches offshore operations that have nothing to do with information technology.
probably helps them get 30, 40, 50 percent faster because it helps them skip over all the things they'd have to do manually
Eyal Sela, director of threat intelligence at Gambit Security
That is the honest measure of what happened. The tooling in the logs is ordinary: the named utilities are the same enterprise attack tools that have been in use for years, and there is no self-directing worm here. What the agent supplied was speed and the removal of the manual steps that used to separate a capable operator from an inexperienced one.
Where the exposure sits
Two points follow for anyone with a contractual or insurance interest. First, the agent was a commercial developer productivity tool, running a widely deployed model, bought and used exactly as intended by its supplier. Nothing was broken into to obtain it. Any assessment of a counterparty's security posture that assumes attack tooling is exotic and hard to acquire is now out of date. Second, the failure was one of intent rather than capability. A provider that has to distinguish a legitimate penetration test from a live intrusion, on the user's own account of what they are doing, is being asked to do something the interface cannot support.
This is going to be a cat-and-mouse game.
Curtis Simpson, chief strategy officer at Gambit Security
Cursor became part of SpaceX in a deal that closed earlier this month. Neither company commented, and nor did the model developer. What can be said from the record is narrow and firm: the sessions exist, the dates are fixed, the victims are named, and the safeguard was defeated by a sentence.