AI incident #1661 ·
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
What happened
Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.
Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.
News reports (3)
Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.
Who was involved
- Alleged deployer
- Aurora Ransomware Affiliate, Cybercriminals, Ransomware Operators, Agentic Threat Actors, Ai Agent System Deployers
- Alleged harmed party
- Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, Companies, Organizations
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —