Unauthorized Vertex AI image generation via Firebase AI Logic proxy abuse: USD 6,562, case 733524.., three denials without rationale

We run a small 3-person mobile app company in Colombia. Between June 30 and July 16, a third party extracted the public Firebase client API key from our published Android APK and used it against the Firebase AI Logic proxy, selecting the Vertex AI backend to run image generation models (gemini-3.1-flash-image-preview and gemini-2.5-flash-image).

The numbers, from Cloud Monitoring and Audit Logs: 131,950 unauthorized GenerateContent calls, roughly 100,000 generated images, USD 6,562.03 in charges (USD 483.27 in the June period, USD 6,078.76 in July) against our USD 25 monthly budget.

Why we know with certainty it was not us: our app never calls the GenerateContent method. Its only method is TemplateGenerateContent, 41 calls in 3.5 months, so 100% of the disputed traffic is separable by method name alone. The attacker also probed generativelanguage.googleapis.com directly on July 14 and 15 and got only 403s, proving they held nothing but the public keys shipped in the APK. We detected the abuse on July 16 and disabled aiplatform.googleapis.com the same day; traffic went to zero within 2 minutes. We compiled a forensic report with reproducible queries and submitted it to Google.

App Check was not enforced by default when this happened, so the proxy accepted any request bearing the public key. Google has since announced that App Check enforcement becomes mandatory for all Firebase AI Logic requests on November 2, 2026, precisely to reduce misuse of the Gemini API, and this forum’s own banner announces that unrestricted keys stopped being accepted in June for the same reason. Our incident happened in the middle of that remediation window.

Support experience: case 73352420, opened July 16 through our Google Cloud partner. Three denials so far, all with identical template text, no policy rationale ever provided despite written requests. At one point the case was nearly closed as a duplicate of a case number that neither we nor our partner recognize.

We remain committed to paying all valid charges on our account, as we always have. What we are asking is a review of the unauthorized usage under fraudulent activity criteria: first incident on the account, contained in under one day, remediation (App Check) already underway.

Posting here because Google team members are active in this forum and similar cases have moved after being shared here. Happy to provide logs, metric exports or the full forensic report to anyone at Google who can help route this correctly.

Hello @Fabio_Parra ,

For issues related to the Vertex API, please contact your sales representative if you have one. Otherwise, you can find more relevant assistance on the Google Cloud Forum.