Urgent: $4,897 Gemini API charge from anomalous traffic, support case #72430631, project suspended

Hi Google AI / Gemini API team,

I need urgent help with an unexpected Gemini API billing issue and project suspension.

Support case ID: #72430631

Project: CalTally

Project ID: calltally-e437..

Billing account: Firebase Payment

Charge: US $4,897.03 for June 1–20, 2026

Main spike date: June 18, 2026

Service: Gemini API / Generative Language API

We have been using the Google Gemini API for almost 2 years, and our normal usage is around ~$3/month. Nothing like this has ever happened before. We have been loyal Google Cloud/Gemini users with a clean usage history.

After checking Cloud Billing and Monitoring, almost 100% of the charge came from Gemini API usage. Around 1.65M requests were made through one API key in under 2 days, peaking around ~75 requests/sec. Other API keys had fewer than 700 requests combined.

I want to be clear: I did not share this API key with anyone, did not authorize this usage, and this traffic had no value for my app/business. This appears to be anomalous or abusive Gemini API traffic far outside our normal usage pattern.

The project was suspended after the spike, and I have not received a proper resolution through support yet.

I’m requesting:

1. A billing adjustment/refund for the unexpected $4,897.03 Gemini API charge

2. Reinstatement of the suspended project

3. Escalation to the billing/Gemini API/security team for investigation

4. Guidance on hard quota/spending controls, API key restrictions, and logging

Can someone from Google please escalate case #72430631?

Hoping a Google Cloud Community moderator or manager can escalate this thread urgently. A sudden jump from a $3 baseline to nearly $5,000 within 48 hours is a severe billing anomaly that clearly indicates automated or abusive traffic. Given that the project is suspended and support hasn’t responded, this needs to be routed to the internal billing escalation team immediately. Upvoting for visibility.

This is a textbook anomaly, not user behavior. A project with a $3/month baseline jumping to $4,897 in a single day via one key — 1.65M requests at 75 req/sec — is the exact pattern Cloud’s own anomaly detection should have caught and auto-paused within minutes. The fact that it didn’t, and that support has gone quiet, is the real issue here. You’ve already done the right things (rotating the key, adding restrictions, tightening quotas). Google needs to meet you halfway with a real investigation, not leave a loyal customer holding a five-figure bill. Bumping this so it gets the attention it deserves. :folded_hands:

You should scan all your code base for malicious library or malware that target llm providers keys.

I saw $17k in a matter of hours, peaked at 104 requests per second. From a service account credential using the generative language API. Investigating now, ticket opened.