My Google Cloud project was suspended on 21 July 2026 for “abusive activity consistent with hijacked resources”. It runs my live subscription product (my main source of income) and it is now completely down. Paying subscribers cannot access what they paid for, and I am losing customers by the hour.
What happened: a Gemini API key belonging to the project was compromised and used by a third party for image generation on 20 July. I confirmed this from Cloud Billing (still accessible): SKUs “Gemini 2.5 Flash Native Image Generation - Gemini API” - about $2 worth of unauthorized API calls. Not my workload.
What I have already done, within hours: deleted the compromised key via AI Studio, rotated every other credential that showed unauthorized use, and ran a forensic review of my server - no host compromise, the leak was limited to the API key.
Why I’m stuck: every management API returns Permission denied: Consumer ‘projects/{project_name}’ has been suspended, even with Owner credentials, and the console redirects everything to the appeal form. So the remediation the suspension notice
demands is impossible to perform. I also cannot buy Standard or Enhanced Support to reach a human, since both require an Organization resource this account does not have, and the free billing chat is unavailable to me.
Appeal filed 21 July 2026, ticket reference ID YJ65HT5PKS5FDASU2C73BWIJ5Q. My app only uses Firestore / Firebase Auth / Storage and never creates Compute resources, so any compute workload in the project is not mine by definition.
Is there anyone from the team who can get this case looked at? I will provide billing evidence, forensic output, or anything else needed. I relaly need help with this, PLEASE!