Compromised Gemini API key racks up $27K over a weekend, Google Cloud denies billing relief

Mysterious_Image_609 · reddit · 2026-09-21

A long-time Google Cloud customer had a Gemini API key compromised, racking up $27,000 in unauthorized charges between Friday and Monday. They only realized the severity when their credit card was declined, then immediately deleted the credentials.

Google billing support denied any adjustment, saying the API calls were validly processed, and the account team said it had no control over billing reversals. A key detail: GCP's spend-cap feature had only recently become available in the console, and the customer wasn't aware they could configure it for that usage — though they had spend controls on Google AI Studio. They acknowledge credential security is their responsibility and have since added spend controls, anomaly detection, and billing alerts.

Original post →

More from Safety

Safety channel →