Unauthorized Access And Fraudulent Charges On Cursor Ultra Account

I am a subscriber to the Cursor Ultra plan at $200 per month, and my account was compromised on May 14, 2026. An unauthorized person gained access to my account and performed two transactions that I did not approve: a $200 USD subscription upgrade to the Ultra plan, which was successfully charged to my Visa debit card ending in 9764 via Stripe with invoice number BZXAQE4Q-0006, and a second attempted purchase for a $1,920 USD annual subscription, which is still listed as open and has not yet been processed. I did not authorize either of these transactions and consider them fraudulent. On May 14, 2026, I immediately contacted Cursor support and opened ticket T-C62626. In response, I received an automated email from “Sam from Cursor” confirming the ticket, providing basic security recommendations such as resetting my password, revoking sessions, and enabling two-factor authentication, and stating that my case had been forwarded to a teammate for investigation of the unauthorized activity and handling of the refund. Since then, I have not received any follow-up with a concrete resolution, cancellation, or refund confirmation. In the meantime, I have already secured my account as instructed. The $200 USD charge was processed through Cursor’s payment system using Stripe, directly from my Visa debit card ending in 9764. Due to the incident happening late at night in my country (Peru), I have not yet been able to reach my bank, but I will be calling them as soon as possible to report this fraudulent charge and request a chargeback if necessary. In light of the above, I request the immediate cancellation of the open $1,920 USD annual subscription invoice and a full refund of the unauthorized $200 USD charge linked to invoice BZXAQE4Q-0006. In addition, I expect a thorough security investigation into how my account was accessed without my consent, written confirmation that the open $1,920 invoice has been cancelled, written confirmation that the $200 refund has been processed, and detailed information about the unauthorized activity on my account, including IP addresses, timestamps, and actions performed by the attacker. I kindly ask that this issue be treated with urgency given the clear signs of unauthorized access and financial risk.













