logo

Stolen Gemini API Key Turned $180 Bill to $82000 in Two Days

ID: 4d3b2985-b69f-56f0-bc88-f7d659d504b9

STIX ID: report--4d3b2985-b69f-56f0-bc88-f7d659d504b9

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

A Mexican three-person development team had a Google Cloud API key stolen and abused to call Gemini 3 Pro Image/Text endpoints, producing $82,314.44 in unauthorized charges within 48 hours (a ~455x increase from their normal $180 bill). The report attributes the root cause to exposed/unrestricted legacy API keys and insecure defaults, notes difficulties obtaining billing relief from Google, and advises controls such as hard spending limits, scoping API keys, using short-lived credentials, and enforcing API quota caps to prevent similar automated account drain attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.