Unauthorized Gemini API usage caused $3,700 bill — billing dispute stalled after specialized-team escalation

Here is a copy of a letter I sent last week to Google. As of today I have received no response. I have redacted some details to protect the confidential info.

I am requesting formal escalation of my billing dispute regarding unauthorized Gemini API usage that resulted in approximately $3,700 in charges.

Timeline:

  • In April, I was notified of unusual / unauthorized Gemini API usage.
  • As soon as I became aware of the issue, I revoked the affected API key.
  • I took down the application involved so no further usage could occur.
  • I filed a billing appeal and provided the requested information.
  • After several emails back and forth, the matter appeared to be moving toward a credit or billing adjustment.
  • I was then told the matter had been forwarded to a specialized team and that I would receive an answer within 24 hours.
  • It has now been more than 10 days since that message.
  • I have followed up at least three times and have not received a meaningful response.

I am asking for the following:

  1. Written confirmation that this case is still active and under review.
  2. Written confirmation that the disputed amount will be placed on hold while the review is pending.
  3. Confirmation that the disputed balance will not be sent to collections, charged again, or reported negatively while the case is unresolved.
  4. A clear status update from the specialized team.
  5. A target date for final resolution.
  6. Escalation to a supervisor or billing-risk specialist if the specialized team has not responded.

This was not legitimate usage by me. The charges resulted from unauthorized use of a compromised API key, and I acted immediately to revoke the key and disable the affected application once notified.

Please treat this as a formal escalation request and provide a written response within 48 hours.

Please everyone, be very careful if you use gemini or don’t use it at all!!!