Students are surprised to get a Google Cloud bill of Rp 920 million due to a Gemini API key leaking on GitHub

A student reportedly received a Google Cloud bill of 55,444 US dollars which if converted it reached around Rp. 920 million. This bill came after the API key of his Gemini service was accidentally uploaded to GitHub and was misused thousands of times by unknown parties.
This case was first shared by a Reddit user with the account name Sandrikkk in the R/GoogleCloud community. He admitted that he only registered for Google Cloud using campus email for study purposes and took advantage of free credit worth 300 dollars that was given to students.
The key of the fire is uploaded without realizing it
The student explained that on June 6 he accidentally pushed (push) the Gemini API key to the Github repository. He believes the repository is private, but actually the key of the fire is seen in one commit. Because it was summer break, he rarely opened the campus email so he didn’t realize that the key had been spread and misused.
He only found out about this problem on September 7 when another GitHub user contacted him and told him that his API key had been open for a long time and was being used by someone else.
When he checked his Google Cloud account, the total bill had already reached 55,444 dollars. The attack resulted in more than 14,200 fire requests in just two days, including many failed requests at a rate of 100 percent.
Google refuses bill cancellation
After realizing the incident, the student immediately revoked the API key, contacted the Google Cloud billing team, and made a police report. He also submitted all evidence in the form of a usage log, GitHub link, and related documents.
However, the results of Google’s investigation state that fixed fees must be paid. Google said there was no change or cancellation of the bill even though the case was clearly an abuse due to a leaked API key.
According to the student’s confession, he never confirmed any transactions, only used student free credit, and was not subject to direct billing because the card stored in the account had expired. Even so, Google still demands payment and warns that if it is not paid within ten days, the bill will be transferred to the collection agency.
unable to pay
The student came from Georgia, a country with an average daily income of around 15 dollars. He said it was impossible to pay such a large bill, even if he worked for decades.
He also said he had read that Google sometimes removed similar debts in certain cases so he hoped there would still be a way to file a higher escalation. But until now Google has not given any leeway.
important lessons for developers
This case is a strong reminder for developers and students who work with cloud services. Some of the most recommended preventive measures include:
Always protect the fire lock safely.
Never upload files that contain sensitive information to GitHub, even on private repositories.
Enable the usage limit or spending limit on the cloud account.
Use the notification feature for suspicious activity and unreasonable billing.
This student closed his post with a message that one small mistake could turn into a nightmare. He appealed to anyone who works with cloud services to be more careful and re-examine what they upload to the public repository.






















