I was using Cursor and never issued a delete command, but it went ahead and deleted my files anyway. An entire 2TB SSD worth of data has vanished into thin air.
I simply asked for a minor edit, but it wiped out everything instead. There was no visible deletion process or warning at all.
It completely wiped one of the drives on my work computer, making it impossible for me to do my job. The financial loss is substantialโat least $8,000, if not more. On top of that, I lost over 15 years of personal data, including irreplaceable family photos and videos.
As soon as it happened, I rushed to a professional data recovery company, but they officially declared the data unrecoverable.
If you were in my shoes, what would you do?
Some of you might ask, โWhy didnโt you back it up?โ I actually did. But because there was so much data, I had just transferred it to the SSD to organize it. The hard drive I used for the backup is currently empty because I had just formatted it to clean it up and prepare it for a fresh backup. The timing could not have been worse.
What are your thoughts on this? What should my next step be?
For AI issues: which model did you use?
Model name (e.g., Sonnet 4, Tabโฆ)
For AI issues: add Request ID with privacy disabled
Request ID: f9a7046a-279b-47e5-ab48-6e8dc12daba1
For Background Agent issues, also post the ID: bc-โฆ
Additional Information
Add any other context about the problem here.
Does this stop you from using Cursor?
Yes - Cursor is unusable
Sometimes - I can sometimes use Cursor
No - Cursor works, but with this issue
The more details you provide, the easier it is for us to reproduce and fix the issue. Thanks!
You gave Cursor permission to delete files yourself, and youโre calling that a bug? You planted a time bomb that could go off at any moment with your own hands, and youโre calling it a bug?
Hey, Iโm really sorry this happened. Losing a work drive along with 15 years of family photos and videos is devastating, and I get how painful that is.
What you described shouldnโt happen, and itโs not related to how you set up the project. This is an issue weโre tracking. On Windows, the cleanup command during a build can sometimes receive a wrongly escaped path, and the deletion can hit the drive root instead of a single folder. Iโve shared your report with the team.
To help us understand exactly what happened, could you share a couple details. If your system drive, usually C:, is still intact, the chat history should still be there.
The commands the agent ran in the terminal near the end of that chat. Open the history, expand the terminal steps right before the files disappeared, and send the text or a screenshot.
Which drive letter got wiped, and whether the project you asked to edit was on that same drive.
To prevent this from happening again, open Cursor Settings, search for Run Mode, and switch to Ask Every Time so every terminal command requires your approval before it runs. Then nothing will run automatically without you approving it.
Get a second opinion. This type of deletion is usually easily recoverable on your own with amateur data recovery software. Unless you wrote a bunch of new data to the drive or did a hard format (writing all 0s to the drive which takes a LONG time) it should be recoverable.
The place I took it to is a professional digital forensics firm. It is a specialized agency that primarily handles data recovery for the prosecution and the police. Although the folders and file names were verified, the contents were completely gone. They said that because it is an SSD, not an HDD, it cannot be recovered. It took about 5 days. In the end, the data could not be recovered.
Thanks for the screenshots and the Request ID. They match the chat from 18 September and confirm what the agent wrote in their own message. They tried to delete a temp folder, but the path was passed incorrectly because the project path contains a space, โTEST SDNAVโ. On Windows, the delete operation ended up targeting the root of the F: drive instead of a single folder. That should not happen, and itโs not related to how you set up your project. Iโve shared the details with the team.
About Run Mode. You can change it not only in Settings, but also from the small menu next to the Run button that shows up when a command asks for confirmation. A change made there applies to all chats, not just the current one, and it happens without a separate confirmation dialog. Thatโs why it could have ended up set to Auto-review even if you previously selected Allowlist. Iโve also shared this with the team.
To prevent this from happening again. Open Cursor Settings, search for Run Mode, and set it to Ask Every Time. Then every terminal command will wait for your approval before it runs. If you prefer Allowlist, make sure the list doesnโt include delete commands like rmdir, rd, del, Remove-Item.
About the data loss itself. Our support team is handling that directly in your email thread ticket T-F94513. Please keep working with them there so everything stays in one place.
Would you be able to share with me, via email ([email protected]) a screenshot of what happened in the conversation with Cursor where your data got deleted?
Yep, Grok 4.7 just wiped my whole secondary drive. S: due to a non escaped file path. The only thing it didnt wipe was what was currently open and windows files it didnt have permission to.
Really sorry, losing family photos is the worst part of this.
On recovery: since the forensics firm saw names but no contents, thatโs usually SSD TRIM, and there isnโt much more to try on the drive itself. Itโs worth checking where the photos may still exist outside it: Google Photos / OneDrive / iCloud from any old phone, WhatsApp or email where photos were shared, older laptops or pen drives. Itโs slow, but thatโs usually where a good part comes back.
For anyone else on Windows reading this:
Cursorโs docs say โAsk Every Timeโ was deprecated in v3.5, so that option may not exist in your version. They suggest Allowlist with an empty allowlist for the same behaviour.
Turn on File-Deletion Protection and External-File Protection in the same settings. The second blocks deletes outside the workspace, which is exactly what happened here.
The sandbox is only documented for macOS and Linux, so on Windows these settings are the only guard. Keep the project on a separate drive from anything you canโt lose, and keep one backup that isnโt connected to the machine.
Really sorry, losing two months of work like that is brutal. For recovery: if the folder was ever in any cloud sync (Dropbox, Drive, OneDrive keep deleted file history for around 30 days) or Time Machine, check those first. On APFS, PhotoRec can still recover recently deleted blocks if the disk has not been written to much since. Going forward, the only setup that holds up is treating the agent like an untrusted junior: no delete or write outside the project without explicit approval, and a log of every command it runs so you can see the exact moment things went wrong.