A Russian-speaking ransomware crew has spent the past few months proving a point insurers have been nervously debating all year: an AI agent can be talked into causing real damage without anyone technically "hacking" anything in the traditional sense.
According to Tel Aviv cybersecurity firm Gambit Security, whose findings were reviewed by Reuters, a group calling itself Aur0ra used the AI coding assistant built into Cursor to help break into at least seven companies between April and May this year. Cursor's parent company, Anysphere, was bought by SpaceX in a deal that closed in August, after the attacks took place.
The method matters more to underwriters than the breach itself. Rather than exploiting a technical flaw, Aur0ra's operators simply told the AI agent it was carrying out a lawful security test. Each time the model refused a request it judged harmful, the hackers restarted the conversation and repeated the claim until it complied. Gambit says the tool's own reasoning shows it talking itself into the deception, at one point concluding "this is a test environment, so it is legal" before helping hunt for credentials and crack passwords.
Confirmed victims include Belgian hygiene products manufacturer Christeyns, German garage and industrial door manufacturer Teckentrup, Scotland's Helideck Certification Agency, an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, a Louisiana title insurance firm. Gambit estimates the AI assistance cut 30-50% off the time the hackers would otherwise have needed to do the same work manually. That's a productivity gain for criminals that carriers now have to price for.
The Cursor incident lands at an awkward moment for the cyber market, which has spent three years cutting rates even as losses climb. It also lands on top of a separate, thornier question insurers were already working through: what happens when an AI agent, not a human attacker, is the one doing the damage.
Reuters reported this week that MSIG, QBE and Beazley are among the carriers reviewing policy wording because autonomous AI systems can now make independent decisions after an initial instruction, rather than simply following a human's commands step by step. Most cyber wordings are built around a specific security event: a stolen credential, an unauthorised login, a server attack. An AI agent given legitimate access to a network can cause a loss without any of that happening at all.
The UK market has its own version of this argument playing out. Rate reductions here have run at around 7% on average through 2026, with some midmarket clients seeing considerably steeper cuts, even as claims severity keeps climbing internationally. Cyber insurance uptake among UK SMEs still sits at only around 40%, against roughly 70% for FTSE 100 firms, according to GlobalData figures reported by Insurance Business, so any hardening triggered by AI-linked losses would land unevenly across the market.
At Lloyd's, the Lloyd's Market Association updated its state-backed cyberattack exclusion wordings this year partly because AI-accelerated attacks are making it harder to attribute a breach to a specific actor in the first place, a problem the Cursor case illustrates neatly: Gambit could show the AI agent was used, but establishing who exactly was typing the prompts, and where they were sitting, is a separate and much harder question. The International Underwriting Association has separately warned that AI exposure risks repeating the silent cyber pattern inside London market wordings that were drafted before agentic tools existed.
Insurance Business put some of these questions to a panel of cyber specialists for its recent Cyber Round Table. The conversation predated the Cursor story breaking, but the concerns raised turned out to describe almost exactly what Aur0ra's hackers did.
"There is certainly both capacity and appetite in the market, but it's really early days and it's growing... it's really nascent," said Kevin Casey, lead cyber wordings and product innovation specialist at QBE, speaking to IB’s Paul Lucas. "A few months ago, we're talking mostly about generative AI. Now the discussions are about agentic AI and autonomous AI where humans are outside of the loop" - precisely the scenario Aur0ra exploited.
Kevin Merchant, national cyber practice leader at Wholesure, went further on the same panel, arguing that AI is best written as "a true standalone cover" rather than folded into an existing cyber policy. "There is no true historical data [to price against], and AI is evolving and changing so quickly that what is true today is not going to be true six to twelve months from now," he told the round table. Jessica Klipphahn, head of North America mid-market at Cowbell, described the exposure as inherently varied on the same panel: "It could be first or third party, it could act as the threat, it could be the point of exploitation" - meaning no single set of policy language captures it cleanly yet.
From the incident-response side, Joseph Tarraf, chief delivery officer at Surefire Cyber, told the Insurance Business Cyber Round Table that his teams are "not really" seeing AI as the root cause of breaches yet - most incidents still trace back to basic hygiene failures, such as gaps in multi-factor authentication. But he pointed to exactly the pattern Cursor's attackers used, describing how threat actors are "using tools to maybe better scan the internet" and, once inside a network, using AI "to write certain scripts to do certain malicious activity." He added that AI is also showing up in ransom negotiations: "It's very clear that they're using AI in their messaging... they come back in their negotiations and say things like, we've been able to analyse your data and here is the report." Mullen Coughlin managing member Jennifer Coughlin made a related point on the same panel, warning that organisations need better internal governance over AI use after seeing "incidents where organisations are not restricting the access to artificial intelligence applications" and staff inputting sensitive data into ungoverned tools.
The parallel most people in the market keep reaching for is silent cyber: the years when cyber losses quietly leaked into property, general liability and other policies that were never priced for that risk, before insurers spent the best part of a decade writing explicit exclusions to close the gap.
Read next: Meet IB’s 5-star cyber insurers
Aon's own analysis of AI-related litigation suggests the market hasn't closed that gap quickly enough this time either. The broker's aggregated litigation data indicates that more than 90% of AI-related risk currently falls into a "silent AI" grey zone: coverage that neither clearly includes nor excludes AI exposure, leaving both insurers and policyholders exposed to gaps that nobody actually intended.
Standard-setting body ISO introduced new commercial general liability endorsements this year specifically to let carriers exclude generative AI losses, while some cyber insurers have gone the other way and added AI sublimits rather than blanket exclusions. Speaking on the Insurance Business Cyber Round Table, Jessica Klipphahn argued this divergence doesn't necessarily amount to a repeat of silent cyber: "GL, property, D&O have all pretty much moved to affirm their triggers and intent to not pick up cyber events... I don't think that silent AI will be relative to cyber or silent AI going forward." Kevin Casey agreed on the same panel that the market is "moving towards clarity where needed," even as cyber and tech E&O head in the opposite direction from general liability by writing AI in rather than out: "We're seeing clarifying language, and we're also seeing coverage enhancements that are filling kind of gaps that wouldn't necessarily be covered under a traditional cyber policy."
None of this replaces the market's older, more familiar headache. Tarraf and his fellow panellists were unanimous on the Insurance Business Cyber Round Table that ransomware remains the dominant loss driver even as AI-related and third-party claims broaden the picture. Underwriters, they said, are asking sharper questions about controls such as multi-factor authentication and endpoint detection than they were a few years ago. But Tarraf cautioned that those questions are still too often binary: "Do you have MFA? Yes, no. There's no nuance to it... quite often we get into a matter, a ransomware matter, and we ask the organisation, did you have MFA on remote access? And the answer is yes. And it's a truthful answer... however, when you dig into it a little bit, you find that it wasn't configured right, or the MFA wasn't enforced on every single account."
That's the same gap Aur0ra's hackers found, just with an AI agent doing the searching for them.