Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

April 8, 2026

Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion. …through contributors—JOIN US—to learn more.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
aurora-ransomware-affiliate, cybercriminals, ransomware-operators, agentic-threat-actors, ai-agent-system-deployers
Alleged developer
anysphere, anthropic, ai-agent-system-developers, large-language-model-developers
Alleged harmed parties
christeyns, teckentrup, helideck-certification-agency, bayou-title, companies, organizations

AI governance case studies

For forensic AI governance failure analysis (TAIMScore™ case studies), browse Human Signal’s Failure Files™.

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1661

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.