# Google Cloud Customer Hit With $18,000 Bill After API Key Attack

_Wednesday, April 22, 2026 at 2:13 PM EDT · Infrastructure, Cybersecurity · Latest · Tier 2 — Notable_

![Google Cloud Customer Hit With $18,000 Bill After API Key Attack — Primary](https://cdn.mos.cms.futurecdn.net/YGsMMUMGmWx6peWh8ZooKC-1920-80.png)

A Google Cloud customer in Australia received a bill of $25,672.86 AUD (approximately $18,391.78 USD) after an attacker exploited a public API endpoint, despite the account having a budget set at $10 AUD (approximately $7 USD).

Jesse Davies, founder of Agentic Labs, said in a LinkedIn post that the attacker found a Cloud Run service he had published from Google AI Studio months earlier. The attacker hit the public URL, and Google's proxy signed each request using an API key stored as a plaintext environment variable in the container. Davies noted that the link was not shared or indexed publicly.

By the time Davies received a budget alert the following morning, A$10,000 had already been charged to his credit card. While he was in contact with Google support, another A$15,000 came through.

Davies said he had followed security practices including per-project API keys, separate billing accounts, two-factor authentication, and Cloud audit logging. He also found nine Google Cloud safety features that should have prevented the incident but were turned off by default.

During the attack, Google automatically upgraded the account from Tier 2, which had a $2,000 limit, to a higher tier with a cap between $20,000 and $100,000. The upgrade occurred when the account crossed the $1,000 threshold. Davies said it took several days to reach a human support representative. The charge has since been waived.

Other users reported similar incidents. One commenter in Japan said they were hit with a $44,000 bill that ballooned to $128,000 even after pausing the API. Cybersecurity firm Truffle Security has highlighted risks associated with Google Cloud's use of a single API key format, noting that existing project identifiers become Gemini API credentials when the Gemini API is activated.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/artificial-intelligence/google-cloud-customer-wakes-up-to-usd18-000-bill-despite-usd7-budget-thanks-to-forgotten-public-api-key-attacker-put-in-60-000-requests-and-blasted-through-usd1-400-spending-cap)

---
Canonical: https://techandbusiness.org/newswire/9qHsvqyKF4agZO92XKKqrt
Retrieved: 2026-04-22T20:43:16.181Z
Publisher: Tech & Business (techandbusiness.org)
