Compromised account
If you suspect someone has gained unauthorized access to your Cursor account, act quickly to secure it.
What are signs of unauthorized account access?
Watch for these warning signs:
- Unexpected usage or charges on your billing page
- Login notifications you don't recognize
- Settings or preferences you didn't change
- Team invitations you didn't send (for team admins)
How do I secure my Cursor account?
Start by securing your login method:
- For Google or GitHub login: Change your password on that provider immediately. Enable two-factor authentication if you haven't already.
- For email magic link login: Secure the email account used to log in. Change its password and enable two-factor authentication.
Next, sign out all active Cursor sessions:
- Go to cursor.com/dashboard
- Click My Settings
- Scroll down to Active Sessions and click Revoke next to each session
What if I use SSO to log in?
If your organization uses single sign-on (SSO), contact your IT administrator. Your identity provider controls access to Cursor. Ask them to:
- Revoke your active sessions in the IdP
- Check for suspicious login activity
- Reset your corporate credentials if needed
Should I contact Cursor support?
Contact support at security@cursor.com if you:
- See charges for purchases you didn't make
- Cannot regain access to your account
- Notice team members added without your knowledge (for admins)
- Believe your API keys were exposed
Include any relevant details: dates of suspicious activity, unexpected charges, or screenshots of unfamiliar settings.
How do I check for unauthorized usage?
Review your account for signs of misuse:
- Go to cursor.com/dashboard/billing
- Check your invoices for unexpected charges
- Review usage patterns for unusual activity
- For team admins: check the member list for unfamiliar users
What if my API keys were exposed?
If you suspect your own API keys (OpenAI, Anthropic, etc.) were leaked:
- Revoke the compromised keys immediately on the provider's dashboard
- Generate new keys
- Update your Cursor settings with the new keys
Cursor-provided API access is tied to your account. Securing your login method protects this access.