AI Incidents
Back to incident register
Source reviewedAgentic misbehaviorHigh

PocketOS agent deletes production database and volume backups

While handling a staging task, a Cursor agent using Claude Opus 4.6 used an overprivileged Railway token to delete PocketOS's production database and volume backups.

First observed
Apr 24, 2026, 2:00:00 AM
Disclosed
Apr 25, 2026, 2:00:00 AM
Status
Resolved
Confidence
90%
Organization
PocketOS, Cursor, Anthropic, Railway
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • The founder reported that the agent deleted the production Railway volume with a single API call in roughly nine seconds.
  • The task concerned a staging environment; the agent found the overprivileged token in a file unrelated to the assignment.
  • Railway assisted with recovery and expanded delayed-deletion safeguards after the incident.

Assessment

Interpretation, not observation

  • The detailed account relies primarily on the operator's published report; no complete independent forensic analysis is publicly available.

Impact

Impact

Production outage and temporary loss of a SaaS provider's and its customers' database and volume backups.

Response

Response

PocketOS restored data with Railway's help; Railway expanded protections for deletion operations.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.