AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

AI Incident Database · article · Aug 27, 2026 · UTC

Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.

Read original source ↗ Open in workspace

recordType
incident-report
evidenceStatus
reported
region
Global

Reported occurrence date: 2026-04-08T00:00:00.000Z

Evidence & attribution

AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.

License: CC BY-SA 4.0

First collected: 2026-09-19T22:50:59.123Z. This is not the publication date.

Observed changes

AIIC observation times, not verified publisher revision times. Up to eight recent revisions.

2026-09-20T23:22:28.549Z

  • publishedAt: Not provided2026-08-27T00:00:00.000Z