AI incident #1661 ·

Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

What happened

Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (3)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

  1. Caught in 4K: The Aurora Files
    cloudsek.com · CloudSEK, CloudSEK TRIAD · AIID #7855

Who was involved

Alleged harmed party
Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, Companies, Organizations

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries