Google Cloud customer wakes up to $18,000+ bill despite $7 budget, thanks to forgotten API key in published project — attacker put in 60,000+ requests and blasted through $1,400 spending cap

TL;DR AI
2 min readKey summary
An Australia-based AI consultant says a public Cloud Run service tied to his Google Cloud project was abused after an exposed API key was found.
The attacker reportedly made more than 60,000 Gemini API requests, triggering charges that surged well beyond the user’s budget alerts and spending cap.
Google initially billed the account at a higher tier, but the company and the user’s bank later reversed the charges.
The case highlights how exposed cloud resources and default billing behavior can still produce major surprise costs, even with some safeguards in place.
