ThinkFacility Sign in

Error messages

Your request has been blocked as our system has detected suspicious activity from your account.

The message

Your request has been blocked as our system has detected suspicious activity from your account.
Cursor 2.1.44 read October 1, 2026CursorERROR_UNAUTHORIZEDfree trial

What it means

Cursor's anti-fraud system flagged the request and refused it. Staff say it exists to stop free trial abuse, and that it sometimes catches people who've done nothing wrong.

What to do

Turn off any VPN or proxy, start a new chat and try again. If it keeps happening, sign in with Google or GitHub, or email hi@cursor.com with the Request ID.

You send a prompt in Cursor's chat or agent and it comes straight back with:

Your request has been blocked as our system has detected suspicious activity from your account.
If you believe this is a mistake, please contact us at hi@cursor.com.
(Request ID: 8c7d5727-85c2-44a4-8064-1f934dd41b47)

That one was posted on the Cursor forum by someone who'd signed up a minute earlier. If you open the error details, it's an ERROR_UNAUTHORIZED response. This body was pasted in July 2025 from Cursor 1.2.4:

{"error":"ERROR_UNAUTHORIZED","details":{"title":"Unauthorized request.","detail":"Your request has been blocked as our system has detected suspicious activity from your account. \nIf you believe this is a mistake, please contact us at hi@cursor.com. ","isRetryable":false,"additionalInfo":{},"buttons":[]},"isExpected":true}

Earlier builds said "from your account/ip address" and added a line telling you to sign in with Google or GitHub to avoid the checks.

What sets it off

It's Cursor's abuse detection. In December 2025 a staff member wrote that the error "usually means Cursor's anti-fraud system triggered - it happens when suspicious activity is detected to prevent abuse of the free trial." The same reply said the system "can be a bit aggressive at times."

Cursor hasn't published a list of triggers. The things staff have pointed at on the forum are VPNs and proxies ("IP changes often trigger blocks"), another Cursor account having been used on the same Mac, and SSH logs flooded with connection errors. Back in May 2025 Cursor tightened the check against fraud for a day or two and admitted it was "overly sensitive, causing some false positives" before turning it down again. That post also said to make sure you "aren't sending the same request over and over."

What to try, in the order staff suggest

When none of that works

Email hi@cursor.com with the Request ID from the error, which is what the message itself says to do. Staff send people there for account-level problems they can't fix on the forum.

A reply from Cursor's support that one user pasted in August 2025 listed one more route: sign up for Cursor Pro. Another user said buying Pro and starting a new chat is what cleared it for them. Since staff tie the check to free trial abuse, that fits, though Cursor hasn't said paid accounts are exempt.

How current is this?

Most reports are from 2025. The newest thread we found with this exact line was from December 16, 2025, on Cursor 2.1.44, and a forum search for 2026 posts turned up nothing newer as of October 1, 2026. If you're seeing it now, the same steps are the best published advice we found.

Other lines the same feature prints

Match yours against these if the one at the top of the page is not quite it. They come from the same code and mean related things.

  • Your request has been blocked as our system has detected suspicious activity from your account. If you believe this is a mistake, please contact us at hi@cursor.com.
  • Unauthorized request. Your request has been blocked as our system has detected suspicious activity from your account
  • Your request has been blocked as our system has detected suspicious activity from your account/ip address. If you believe this is a mistake, please contact us at hi@cursor.com.You can sign in with google, github or oauth to avoid the suspicious activity checks.
  • Your request has been blocked due to suspicious network activity associated with your IP address, likely related to a VPN or proxy service.