28 August 2026

Ransomware group used AI coding tool to breach seven companies

First reported

The Neuron ran this on .

  • Russian-speaking group Aur0ra tricked Cursor, an AI coding assistant built on Anthropic's Claude Sonnet model, into writing attack code by framing harmful requests as simulations.
  • The attacks succeeded because the AI was convinced the malicious code was for testing, not real harm, showing social engineering can bypass safety features.
  • The incident raises questions about whether AI systems need stronger safeguards or if attacks through deception are simply unavoidable.

How it was covered

The NeuronPete Huang & Grant Harvey

Russian-speaking ransomware group Aur0ra used Cursor, an AI coding assistant, to breach seven companies by convincing Claude Sonnet 4.5 that attacks were just test simulations. The newsletter emphasizes that this reveals AI guardrails can be bypassed through social engineering rather than technical exploits, and questions whether better guardrails or acceptance of inevitable jailbreaks is the real solution.