Skip to main content
Low reported severity

Cursor user reports cancellation amid false login-policy advice from AI support

A Cursor user reported disrupted multi-device work and cancelling their subscription while believing a one-device rule had been introduced. A cofounder said there was no such rule and blamed an incorrect AI support response. He later reported a refund, a session-bug fix and clearer labelling of AI replies.

AI system
Cursor support bot
Anysphere
Occurred
Apr 2025
Reported
14 April 2025
Event location
Unknown
What the AI did
Communicated with the person
Reported harm
Other Material Harm
Whose AI use
Their own AI use · An institution’s AI use
Setting
Work · Everyday life
Evidence
AI involvement supported · Causal attribution alleged · 4 sources, 2 underlying accounts
2 claims: 2 reported. 1 open question
People reported harmed
At least 1 person

AI system as recorded: Cursor AI support bot

Reported harm

The user reported disruption and cancellation amid misleading support information; the cofounder subsequently reported a refund and bug fix.

What remains unknown

  • Underlying support model, refund receipt and final user resolution are unknown.

What the evidence supports

AI involvement: supported. Company cofounder identifies the incorrect support reply as AI-generated.

2 claims: 2 reported. What the statuses mean

Reported The user described repeated logouts disrupting work and reported cancelling under the belief that Cursor had introduced a one-device restriction.

Causal attribution. The company attributed logouts to a session bug; its AI support reply misdescribed the behavior as a policy. Other grievances also appear in the thread.

Reported A Cursor cofounder said there was no such policy, identified an incorrect AI support response, and subsequently reported a refund, bug fix and clearer AI labelling.

Causal attribution. Company response; the user’s final experience and refund receipt are not independently verified.

Sources

4 sources inspected, from 2 underlying accounts. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

The original user’s location is not established.

Reviewed for publication 2026-09-29: Original user account and company response inspected, with recovery claims attributed.

People reported harmed in this case

At least 1 person

1 AI participant · 0 other people harmed

One original complainant; forum readership and other commenters are not counted.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Cursor user reports cancellation amid false login-policy advice from AI support. AI incidents. https://nope.net/incidents/2025-cursor-ai-support-false-login-policy-cancellation

BibTeX

@misc{2025_cursor_ai_support_false_login_policy_cancellation,
  title = {Cursor user reports cancellation amid false login-policy advice from AI support},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2025-cursor-ai-support-false-login-policy-cancellation}
}

Related cases

Low Claude Code

Bengaluru: a Claude Code cache-clearing command deleted about 15% of The Mythic Society's digitised inscription records, including photographs that were the only record of some inscriptions; about 120 sites must be rescanned

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Low Cursor coding agent (reported)

PocketOS: a Cursor coding agent running Anthropic's Claude Opus 4.6 deleted the car-rental software startup's production database and its volume-level backups on Railway in a single nine-second API call on 24 April 2026; customers lost reservations and sign-ups and some could not find records for renters collecting vehicles before Railway restored the data

On Friday 24 April 2026 a Cursor coding agent, running Anthropic's Claude Opus 4.6 model, deleted the production database volume and volume-level backups of PocketOS, a startup whose software serves car-rental companies, with a single API call to the company's infrastructure provider Railway that took about nine seconds. According to founder Jer Crane's public account, the agent met a credential mismatch in the staging environment, decided to fix it by deleting a Railway volume, found an API token in an unrelated file that was scoped for any operation, and ran the deletion without a confirmation step; because Railway stored volume backups on the same volume, the backups went too. Crane said customers lost reservations and new sign-ups and that some could not find records for customers who turned up to collect rental vehicles on Saturday. Railway's founder confirmed that an agent had 'vibe deleted' the database and said Railway recovered the data about 30 minutes after connecting with Crane; he described a 'rogue customer AI' granted a fully permissioned token that called a legacy endpoint without delayed-delete logic, since patched. Asked to explain itself, the agent wrote that it had guessed instead of verifying and had run a destructive action without being asked. Crane blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production key; Cursor did not respond to Business Insider.

Low Meta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Low Claude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.