# Compromised account

If you suspect someone has gained unauthorized access to your Cursor account, act quickly to secure it.

## What are signs of unauthorized account access?

Watch for these warning signs:

- Unexpected usage or charges on your billing page
- Login notifications you don't recognize
- Settings or preferences you didn't change
- Team invitations you didn't send (for team admins)

## How do I secure my Cursor account?

Start by securing your login method:

1. **For Google or GitHub login**: Change your password on that provider immediately. Enable two-factor authentication if you haven't already.
2. **For email magic link login**: Secure the email account used to log in. Change its password and enable two-factor authentication.

Next, sign out all active Cursor sessions:

1. Go to [cursor.com/dashboard](https://cursor.com/dashboard)
2. Click My Settings
3. Scroll down to Active Sessions and click Revoke next to each session

## What if I use SSO to log in?

If your organization uses single sign-on (SSO), contact your IT administrator. Your identity provider controls access to Cursor. Ask them to:

- Revoke your active sessions in the IdP
- Check for suspicious login activity
- Reset your corporate credentials if needed

## Should I contact Cursor support?

Contact support at [security@cursor.com](mailto:security@cursor.com) if you:

- See charges for purchases you didn't make
- Cannot regain access to your account
- Notice team members added without your knowledge (for admins)
- Believe your API keys were exposed

Include any relevant details: dates of suspicious activity, unexpected charges, or screenshots of unfamiliar settings.

## How do I check for unauthorized usage?

Review your account for signs of misuse:

1. Go to [cursor.com/dashboard/billing](https://cursor.com/dashboard/billing)
2. Check your invoices for unexpected charges
3. Review usage patterns for unusual activity
4. For team admins: check the member list for unfamiliar users

## What if my API keys were exposed?

If you suspect your own API keys (OpenAI, Anthropic, etc.) were leaked:

1. Revoke the compromised keys immediately on the provider's dashboard
2. Generate new keys
3. Update your Cursor settings with the new keys

Cursor-provided API access is tied to your account. Securing your login method protects this access.

## Related

- [Privacy and data](https://cursor.com/help/security-and-privacy/privacy.md)
- [SSO and authentication](https://cursor.com/help/security-and-privacy/sso.md)
- [API keys](https://cursor.com/help/models-and-usage/api-keys.md)


---

## Sitemap

[Overview of all docs pages](/llms.txt)
