AI incident ·
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
In brief
An AI system built by Anysphere, Anthropic and 2 others and deployed by Aurora Ransomware Affiliate, Cybercriminals and 3 others allegedly harmed Christeyns, Teckentrup and 4 others.
- Risk domain
- Not classified
- Occurred
- Coverage
- 3 reports
What happened
Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (3)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Aurora Ransomware Affiliate, Cybercriminals, Ransomware Operators, Agentic Threat Actors, Ai Agent System Deployers
- Alleged harmed party
- Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, Companies, Organizations
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Source record: incident #1661 on the AI Incident Database · all 3 reports