Unauthorized Gemini API usage

Have any of the other users been subjected unauthorized Gemini API usage as per this article https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules ? Any suggestions on best-practice recommendations for approaching and resolving this issue, vis-à-vis a rebate?