URGENT: Project flagged "Compromised" + spend cap reached from fraudulent usage — production down, keys already revoked

Hi all,

I need urgent help from the Gemini API team. My production service is completely down due to the after-effects of an API key compromise, even though I’ve already secured the project.

What happened:

  • My Gemini API key was compromised. Someone ran up €271.48 of usage on my project — far beyond my normal usage (I have never used anywhere near this much).
  • As soon as I discovered it, I revoked the compromised API keys, created a new restricted key, and deleted the orphaned service accounts left behind by the old keys.
  • I have also reported the unauthorized charges to billing support.

Current state — two blockers:

  1. In AI Studio, my project now shows status “Compromised” (orange badge on the Projects page), and requests are failing with 429 RESOURCE_EXHAUSTED errors.
  2. I’m also getting this message:
    “You’ve reached the billing account monthly spend cap and service has been paused.”
    The spend that consumed the cap was the fraudulent usage itself — so the attacker’s traffic has both flagged my project and burned my entire monthly cap, and now my legitimate production traffic is locked out.

Project details:

  • Project: gen-lang-client-00356955..
  • Billing tier: Tier 1 · Prepay
  • Compromised keys
  • Unauthorized spend: ~€271.48

What I’m asking:

  1. How do I get the “Compromised” status removed now that the project is secured? I don’t see a clear remediation/appeal flow.
  2. Can the spend cap be reset or the pause lifted, given the cap was consumed by unauthorized usage and not by me?
  3. Is the correct place for the refund/adjustment of the €270 the billing support case, or is there a separate process for compromised-key incidents?

This is a production application with real users affected, so any pointers to the right escalation path would be hugely appreciated. Happy to provide logs, invoices, or any verification needed.

Thanks in advance!