TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Student Charged $14k on Stolen Google Cloud Credentials

71 点作者 nitins_jakta大约 6 年前
Hi,<p>In 2017, I made a Google Cloud Account to use Google Maps API for a Computer Science student group project and put my debit card in. I naively put a $5 account notification in, thinking it was a cap. This project was defunct after 2017 and I should have just closed the Cloud account.<p>All was fine up until January 2019 when the Google Cloud Credentials were somehow stolen and over the course of two days on Google Maps API, racked up enough API calls to generate over $14k invoice. I disabled the Google Cloud Account a day after I noticed an email from Google Cloud. Google Cloud did try to use debit card to deduct from checking account, but I don&#x27;t leave thousands sitting around in it, so charge was declined.<p>I talked to Google Cloud Billing and they have not been helpful, telling me to contact my bank. Today, I got a scary email from a collections agency demanding I login to my Google Cloud account and pay the bill! Worst part is, this API used to be free, until Google started charging exorbitant amounts for it.<p>I know I did not make these API calls -- if you looked at the call volume history, there was nothing for well over a year, until those two days in 2019, it started going crazy (and the project is not running on any server or being used in any way). I suspect a group member might have accidentally leaked the credentials.<p>I know AWS has waived costs[1] like this in the past, but Google is not known for customer support. I should have been more proactive in setting up a cap.<p>Appreciate any advice or Google contacts to talk to an actual human. Should I see if Google is willing to actually verify this was unauthorized usage or just lower the bill? I&#x27;ll eat a few thousand just to make this go away.<p>To say GCP has left a sour taste in my mouth is an understatement!<p>Thanks for reading.<p>[1] https:&#x2F;&#x2F;dev.to&#x2F;juanmanuelramallo&#x2F;i-was-billed-for-14k-usd-on-amazon-web-services-17fn

10 条评论

boulos大约 6 年前
Sorry this happened to you! Feel free to send me your case number (email in profile), and I&#x27;ll escalate it.<p>The Support personnel have hopefully been helping out, as all Billing Issues are covered regardless of support tier. I obviously don&#x27;t know the ins and outs of payment instrument refunds &#x2F; do debit cards mean that you actually do have to contact your bank, but I&#x27;m sure people in Support do.
评论 #19612005 未加载
评论 #19685278 未加载
scarface74大约 6 年前
I’ve heard so many stories of something similar happening on AWS and after an email to support, all of the charges were dropped.<p>This isn’t exactly helping Google to fight the narrative that it isn’t good with customer support and they can’t be trusted as a platform for business.<p>So if you were a person deciding who to choose as your cloud provider, who are you going to choose?<p>AWS - “No one ever got fired for choosing AWS”<p>Microsoft - well known for their enterprise support and there are plenty of MS Shops out there.<p>Or<p>Google?
评论 #19611385 未加载
segmondy大约 6 年前
While you&#x27;re figuring this out, backup all your data on Google. Google is crazy and could possibly delete all your accounts and data.
评论 #19611417 未加载
unknownkadath大约 6 年前
Before disputing the charge, be sure to back up all data and contact info from your Google accounts. Fighting charges has been known to trigger account lockouts with no appeal.
评论 #19611369 未加载
applecrazy大约 6 年前
Did you check your Github repos and associated commit history for accidental push of secret files? There&#x27;s an article on the HN front page describing secret leakage in Github repos (the most common is Google API keys, go figure)[1]. I imagine somebody out there has a bot to monitor pushes in realtime to extract secrets. You or a team member might have leaked keys in a similar manner.<p>[1]: <a href="https:&#x2F;&#x2F;blog.acolyer.org&#x2F;2019&#x2F;04&#x2F;08&#x2F;how-bad-can-it-git-characterizing-secret-leakage-in-public-github-repositories&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.acolyer.org&#x2F;2019&#x2F;04&#x2F;08&#x2F;how-bad-can-it-git-chara...</a>
londons_explore大约 6 年前
Google will typically waive charges in cases like this.<p>The only time they won&#x27;t is if (by looking at the logs) they decide you were probably scraping and storing all their data.
foobarbazetc大约 6 年前
Make them prove you used it to generate the charges. Make them provide IPs etc.<p>You need to say it was used fraudulently and you don’t agree to the charges.
评论 #19610711 未加载
评论 #19611098 未加载
评论 #19614830 未加载
samfisher83大约 6 年前
Next use a credit card. Basically thanks to credit card laws the bank will go tell google to f off and give you your money back. Debit cards don&#x27;t have the same protection, but just call your bank or OCS (<a href="https:&#x2F;&#x2F;www.occ.treas.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.occ.treas.gov&#x2F;</a>). They have a little more bite.
评论 #19612040 未加载
评论 #19611827 未加载
cjbprime大约 6 年前
Keep trying to talk to them and explain -- so far every instance like this I&#x27;ve heard about was refunded. Good luck.
kkarakk大约 6 年前
I dunno if google lets you do this but amazon&#x2F;azure will pretty reliably let you create new free tier accounts with fake emails and access them from the same IP. i just create a new debit&#x2F;credit card every 6 months(it&#x27;s pretty hassle free in india).<p>i do pay for production instances, i just don&#x27;t want to mess around on those production instances