Unrestricted API key + AI Studio silently enabled Gemini — $14k bill on a small family brazilian tire shop

Thank you, Terry — this is genuinely useful, and the Brazil-specific roadmap especially. I’ve documented all of it. I’m posting this update partly so the thread doesn’t go quiet, and partly so anyone else caught by this knows what the road actually looks like after the bill lands.

Let me be clear about where I stand: I’m not here to fight Google. I’ve trusted my entire stack to this company since 2020 — Workspace and Drive run my law practice, Google Cloud hosts the servers and sites for my other businesses. I still want to resolve this directly and amicably. That’s exactly why the next part is hard to write.

Because over five days I’ve had three live-chat escalations, with three different agents, and each one started from zero.

June 10, within hours of the attack. The billing dashboard showed nothing — no anomaly, no usage, just my father’s card already drained by ~R$37,000. The agent literally could not see the incident, because billing data lags roughly 32 hours. So I was told to “wait for propagation,” handed a spend-cap link, and promised an email update. That email never came.

June 13. A second agent told me she had added a high-priority note, attached my full forensic ZIP, escalated the case to Trust & Safety and Billing Escalation, and placed a hold against automated suspension.

June 15. A third agent submitted a brand-new adjustment request — which can only mean the previous two escalations went nowhere. When I asked for four simple things — the case status, a tracking number for the adjustment, an SLA, and written confirmation that the specialized team had ever actually opened the file — I got “we are unable to disclose internal information,” and another round of “rest assured.”

Here is the part that should worry Google, not me: the people hit hardest by a flaw Google itself is patching on June 19 are being routed into a Tier 1 loop with no case continuity, no ticket for the adjustment, no SLA, and promised emails that don’t arrive. And the billing-propagation lag means the very first agent you reach — in the panic of the first hour — structurally cannot see what happened. The clock starts late, and the entire burden of proof lands on the victim.

It isn’t for lack of evidence. I did the forensics myself, read-only and reproducible, from Google’s own Cloud Monitoring APIs: 593,546 of ~594,000 calls attributed to a single 2021 Maps key; the Dec 27, 2025 audit-log entry where enabling Gemini silently extended access to that unrestricted key; zero third-party admin actions — no compromise, no negligence on my side. I handed all of it over. The evidence isn’t missing. It just has nowhere to land.

And this is not an edge case. Truffle Security disclosed this exact privilege-escalation in February 2026; Google first called it “intended behavior,” then reclassified it as a bug. The root-cause fix lands June 19. My family was charged on June 10 — nine days inside that gap.

So my ask to anyone from Google reading this is simple. I don’t need another “rest assured.” I need case #72154838 to actually reach the specialized team, and one written status update confirming it’s there. @Mustansir_Lokhandwala already confirmed on this forum that the case was escalated — I’m just asking that the escalation be real on the inside, not only on the transcript.

I want to resolve this with Google directly, and I want to keep believing in the company I built my work on. Help me do that.

— Lúcio