Unauthorized Gemini API charges (~₹7.84 lakh / ~$9.5K USD) on production project — abuse resumed 3 days after rotation, billing extension expires tomorrow

Hi all,

Posting alongside our open GCP Support case #70503708 — payment deadline expires tomorrow (May 13), second extension declined this morning by billing chatbot.

Summary: Production GCP project, ~zero Gemini baseline. Google’s own systems flagged compromise Apr 23. We rotated all keys Apr 24. Three clean days followed (Apr 25–27). Then Apr 28: a single 24-hour burst hit 79 Gemini SKUs (text, image, video, audio I/O models we’ve never used) — ₹7,83,722.69 in unauthorized charges on Apr 28 alone. Apr 29 spend dropped 99.85% the moment we disabled the Gemini API.

Case has been with Billing/Finance review ~12 days. Deadline tomorrow. Pattern matches several other very recent reports on this forum (€5k/1hr, $10k/2days, €54k Firebase, $213 with same model-mismatch signature).

Hoping for Google staff visibility on credit-review timing before deadline. Full forensic details available — happy to share on request.

Thanks,
Sanjeev, Younglabs

Hi @YL_DevTeam

DM’ed you for more details

This happened to me today as well. The support chat queue was full, which is quite curious considering this is happening to several people, only with Gemini, and apparently not being considered a problem on Google’s side.