A small three-person software team reported that a stolen Google Cloud/Gemini API key was abused to run up $82,314.44 in charges in roughly 48 hours, a ~455x spike from their typical $180/month spend. The attacker(s) allegedly hammered the Gemini 3 Pro Image and Gemini 3 Pro Text endpoints, and the victim stated they deleted the compromised key, disabled Gemini APIs, rotated credentials, enabled 2FA, and tightened IAM controls while opening a support case.
Both reports indicate Google support initially pointed to the cloud Shared Responsibility Model, signaling the customer may remain liable for charges tied to compromised credentials. The incident was framed as a cautionary example of how exposed or poorly-scoped API keys can become high-impact AI credentials; one report cited research indicating thousands of legacy Google API keys have been found exposed on public websites and warned that default or “Unrestricted” API key settings can enable catastrophic cost exposure unless organizations implement guardrails such as billing budgets/caps, API key restrictions (API/IP/referrer scoping), and tighter quota limits.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Developer Charles Jones said his Google Cloud account was hijacked over June 7-8, 2026, resulting in $11,089.77 in unauthorized charges largely tied to Gemini image-generation usage. Google reportedly linked the abuse to a compromised firebase-adminsdk service account key and suspended the account for activity consistent with hijacked resources.
The affected user reported filing a cybercrime complaint with the FBI and planned to provide logs as evidence of credential theft and API abuse. The filing was part of an effort to support the dispute and seek possible goodwill credits from Google.
Following the incident, the team contacted Google Cloud support to dispute the charges and seek relief. According to the reports, initial feedback indicated the charges would likely stand under Google's shared responsibility model.
After discovering the unauthorized usage, the affected developers deleted the compromised key, disabled Gemini APIs, rotated credentials, enabled 2FA, and tightened IAM controls. These actions were taken to stop further abuse and secure the Google Cloud environment.
Between 2026-02-11 and 2026-02-12, attackers used a stolen Google Cloud/Gemini API key to make large volumes of Gemini 3 Pro Image and Gemini 3 Pro Text requests. The abuse drove charges to $82,314.44, far above the victim team's usual monthly spend of about $180.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecybersecuritynews.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.