HELP! An old test Maps API Key accidentally not deleted was compromised by a malicious person an ran up 34K requests in a matter of a few hours. How can I get out of this $1,200 bill?
It was last Sunday afternoon when I received a notification that my bank declined several attempted $200+ charges from Google Cloud Services.
Upon further investigation I found that my Google Cloud Services had an old test API Key that was never deleted like it was supposed to have been, unrestricted, and connected to my main Google Cloud Services (Google Business) account.
It therefore ran up ~$1,288 bill.
There's virtually ZERO history of any API Keys receiving requests to that account. Then, suddenly out of nowhere there's 34K+.
I never use this particular account for any sort of API Key services. It's strictly been an account for email and YouTube Premium. I've since deleted the key in question and contacted Google Chat Support (I do not have phone support).
The Chat Support told me that my case was "being transferred to a specialized department". I have heard absolutely NOTHING from this specialized department.
Am I totally screwed here?
I have two kids and I don't make a ton of money so this bill is a pretty big issue. I'm afraid to update my billing right now because I have bills to pay and children to feed. But I do not want to lose my Google Account / GMAIL / Email, etc.
EDIT: It was a Google Places (New) API Key