Skip to main content
Infrastructure Security

Google Cloud Customer Hit With $18,000 Bill After API Key Attack

Google Gemini 3 header image Image: Primary
A Google Cloud customer in Australia received a bill of $25,672.86 AUD (approximately $18,391.78 USD) after an attacker exploited a public API endpoint, despite the account having a budget set at $10 AUD (approximately $7 USD). Jesse Davies, founder of Agentic Labs, said in a LinkedIn post that the attacker found a Cloud Run service he had published from Google AI Studio months earlier. The attacker hit the public URL, and Google's proxy signed each request using an API key stored as a plaintext environment variable in the container. Davies noted that the link was not shared or indexed publicly. By the time Davies received a budget alert the following morning, A$10,000 had already been charged to his credit card. While he was in contact with Google support, another A$15,000 came through. Davies said he had followed security practices including per-project API keys, separate billing accounts, two-factor authentication, and Cloud audit logging. He also found nine Google Cloud safety features that should have prevented the incident but were turned off by default. During the attack, Google automatically upgraded the account from Tier 2, which had a $2,000 limit, to a higher tier with a cap between $20,000 and $100,000. The upgrade occurred when the account crossed the $1,000 threshold. Davies said it took several days to reach a human support representative. The charge has since been waived. Other users reported similar incidents. One commenter in Japan said they were hit with a $44,000 bill that ballooned to $128,000 even after pausing the API. Cybersecurity firm Truffle Security has highlighted risks associated with Google Cloud's use of a single API key format, noting that existing project identifiers become Gemini API credentials when the Gemini API is activated.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Tom's Hardware and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...

Security
Security

CrowdStrike investigates Falcon privilege-escalation zero-day

CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform. The expl...