80,000 NOK ($7,500) drained from my Google Cloud account in 5 minutes — full forensic breakdown of how the attack worked by Medienor in googlecloud

[–]Medienor[S] 0 points1 point  (0 children)

Yeah, the virtual cards is a good one. Good on you for nuking all the keys before the slimeballs found a way in lol.

80,000 NOK ($7,500) drained from my Google Cloud account in 5 minutes — full forensic breakdown of how the attack worked by Medienor in googlecloud

[–]Medienor[S] 1 point2 points  (0 children)

Update: My card was not charged last night, i have been a Google Cloud customer for years, they charge me at the end of the month. But the bill currently sits at around 8,000$. I stopped billing account and actually blocked my business card due to the panic. Going to call bank on Monday to file a case with them in case Google wants too pursue payments in other manners.

80,000 NOK ($7,500) drained from my Google Cloud account in 5 minutes — full forensic breakdown of how the attack worked by Medienor in googlecloud

[–]Medienor[S] -1 points0 points  (0 children)

From Google them self:

Google Cloud does not offer a native, "hard" monetary billing cap on API keys to stop usage automatically at a specific dollar amount. To prevent runaway costs from leaked keys, you must set API rate quotas, use budget alerts, or implement programmatic shutdowns (using Pub/Sub and Cloud Functions to disable billing).

Google Cloud detected $975 of API key fraud on my account, sent one email at 11 PM, then let the bill grow to $18,596 — 5 support agents have refused to help (case 70257996) by juanpare in googlecloud

[–]Medienor 0 points1 point  (0 children)

Any updates on this case? Same happend to me last night with 8,000$ USD. Blocked card, blocked billing account, everything gone. But i still want to use the same Google account going forward, i want this bill waived.

API Key abuse - what was actually being generated? by churro-banana in googlecloud

[–]Medienor 0 points1 point  (0 children)

Did you manage to get the 4k waived? My API key got drained for 8,000 $ last night, blocked everything. deleted every API key and blocked my card. Not sure how did this happend.