Theory — the hypothesis held before the instruments answered
“A cloud bill cannot run away from you overnight; there is a ceiling somewhere, and somebody is watching it.”
Date — 2026-06
Symptom
$11,089.77 billed against $0.71 expected — a greater-than-1000% anomaly. Charges accumulated across roughly 48 hours, 7–8 June, before the account was suspended.
Diagnosis
A compromised firebase-adminsdk service-account key. The provider’s suspension notice cited
activity consistent with hijacked resources.
Cure
Moved to a keyless architecture on workload identity federation. Every user-managed key disabled; five plaintext key files shredded, including two that survived in cloud-synced folders and were found only because a previously killed sweep was re-run.
Permanent
Zero plaintext service-account keys anywhere under the home tree, marker-verified rather than assumed. A standing rule now blocks any credential-shaped artifact from entering a long-lived archive — scrub the exported copy, never the read-only source.
Measured
The theory resolved to fact in the wrong direction: there was no ceiling and nobody watching. Project reinstated 2026-06-17. Charges reversed by two banks independently as fraud; the full
$11,089.77 was credited back.
Sources
The Register, 2026-07-03 — case covered, operator named. Google Cloud (official account) — public reply to the operator’s comment on Google Cloud CEO Thomas Kurian’s AI-security post.
The lesson that outlived the incident: a disabled key does not help if a copy is sitting in an archive nobody remembers restoring. The cure had to be the absence of the key, not the revocation of it.