Dev says Google warned him about account hijack then charged him $11,000 anyway
A developer claims Google alerted him to a potential account hijack but still charged him over $11,000 for cloud services used by the attacker. He argues the company should have prevented or reversed the fraudulent charges after issuing the security warning.
Background
- Google Cloud Platform (GCP) offers cloud computing services (servers, databases, etc.) where customers pay for what they use — sometimes automatically through "bots" or scripts that spin up resources.
- "Account hijack" means an attacker gained access to the developer's GCP account and used it to run expensive compute workloads, racking up an $11,000 bill.
- This is part of a long-running pattern: cloud providers (AWS, Google, Azure) have automated billing that can run up huge charges in minutes, and their fraud/support processes often deny refunds even when the customer was clearly hacked.
- The developer's complaint: Google's own security system warned him about the suspicious login — yet Google still demanded payment, refusing to reverse charges. Critics see this as a perverse incentive: if Google profits from the hijacker's usage, it has less financial reason to stop the fraud.