Skip to main content
Solved

Urgent: GCP Project Suspended for Resource Hijacking - Unable to Access IAM to Rotate Leaked Keys

  • April 23, 2026
  • 13 replies
  • 1592 views

rakesh.shrestha
Forum|alt.badge.img+2

Hello everyone,

I am seeking urgent guidance regarding a GCP project suspension. My account was recently suspended, and I received an email stating that the project was engaged in abusive activity consistent with "hijacked resources."

The Situation:

  • Access Denied: My production application is currently offline. Whenever I attempt to access the IAM & Admin or APIs & Services dashboard to investigate, I am automatically redirected to the suspension warning page.
  • Unknown Leak: I have audited my frontend/backend/app environment variables (.env) but haven't found any obvious exposures.
  • Account Lockout: Because I cannot access the IAM dashboard or Cloud Logging, I am unable to identify which credential is being abused or delete the compromised keys.
  • Appeal Status: I submitted an appeal over a week ago, but I have not received a response, and my production app remains affected.

My Questions:

  1. Is there a way to access Cloud Logging or Security Command Center via the SDK or a restricted console view while the project is suspended to identify the source of the abuse (e.g., specific IP addresses or hijacked keys)?
  2. Can I programmatically revoke all existing API keys via gcloud or a similar tool if the web console is locked?
  3. Are there specific channels to escalate an appeal when the suspension is caused by a hijacked resource rather than a policy violation?

Any advice on how to regain enough access to rotate my credentials and secure the project would be greatly appreciated.

Best answer by rakesh.shrestha

I was finally able to resolve this issue. Since the UI redirect completely blocked access to the console, I upgraded to paid support in order to reach a human support agent. Once access was restored, I was able to:

  • Rotate and remove all compromised API keys and credentials
  • Apply strict IP and referrer restrictions to all newly generated keys
  • Provide proof of the implemented security changes for review.

After these remediation steps were verified, the suspension was successfully lifted.

Key Takeaway:
If you are stuck in a redirect loop that prevents access to the console, paid support is a much faster path to recovery than waiting for Google’s standard appeal response. It’s a worthwhile investment to get your production environment back online and properly secured.

13 replies

Sureshbabu
  • New Member
  • April 24, 2026

I am also having this problem of suspension for resource hijacking and charges in Google cloud 5500 rupees 


kentphelps
Community Manager
Forum|alt.badge.img+12
  • Community Manager
  • April 24, 2026

Kragekjaer
Forum|alt.badge.img+2
  • New Member
  • April 25, 2026

I have been waiting for 3 weeks now, it is not acceptable, and will never recommend Google for anyone.


fernandoredondo
Forum|alt.badge.img+3

@Kragekjaer ​@rakesh.shrestha 

After 3 weeks without any reply I got a email to the Google Cloud Console Appeal Notification email, where they asked if I can describe the problem and what steps I took — something I already included in the original appeal.

So now I’ve waited 3 weeks to give Google the same information, and now I guess I have to wait a few more weeks to get a reply to this email.

Any luck for someone else here?


Kragekjaer
Forum|alt.badge.img+2
  • New Member
  • April 27, 2026

This is very frustrating.

I would pay money to get help on this. 


kmrtn
  • Bronze 1
  • May 1, 2026

I agree. This is unacceptable, and unnacceptable to have no recourse to fix ANYTHING look at logs etc. due to getting redirected to appeals page. Even the “Read More” link on the console on the suspension appeal page redirects to the suspesion appeal page. Beyond messed up and ironically means basically google hijacked my project.


rakesh.shrestha
Forum|alt.badge.img+2

I was finally able to resolve this issue. Since the UI redirect completely blocked access to the console, I upgraded to paid support in order to reach a human support agent. Once access was restored, I was able to:

  • Rotate and remove all compromised API keys and credentials
  • Apply strict IP and referrer restrictions to all newly generated keys
  • Provide proof of the implemented security changes for review.

After these remediation steps were verified, the suspension was successfully lifted.

Key Takeaway:
If you are stuck in a redirect loop that prevents access to the console, paid support is a much faster path to recovery than waiting for Google’s standard appeal response. It’s a worthwhile investment to get your production environment back online and properly secured.


rakesh.shrestha
Forum|alt.badge.img+2

This is very frustrating.

I would pay money to get help on this. 

Yes, there is a paid support option, and it was the only way I managed to get this resolved. I upgraded to Standard Support (which starts at around $29/month).


DevDaniel
Forum|alt.badge.img+1
  • Bronze 1
  • May 9, 2026

Hello,

I am seeking assistance with a project suspension that has now exceeded the standard review window. My project, MindfulFlow (id: mindfulflow-613bc), was suspended due to an API key compromise that resulted in unauthorized activity.

Case Details:

Appeal Case ID: [removed by moderator]

Initial Suspension Date: April 21, 2026

Last Communication from Google: April 24, 2026 (Request for additional information)

Status: My detailed response was sent on April 24, but I have received no update since.

Remediation Steps Taken:

Key Revocation: I have already revoked the compromised Gemini API key.

Architecture Fix: I have identified that the compromise occurred because the key was embedded in the Android client. I am migrating the app to use Vertex AI for Firebase with App Check to ensure no keys are exposed in the future.

Security Commitment: I have committed to routing all AI requests through Firebase's secure infrastructure.

My app is currently live on the Play Store, and this prolonged suspension is significantly impacting my users. Could a Community Manager please help escalate this case to the Trust & Safety team for a human review?

Thank you for your time and help.


fernandoredondo
Forum|alt.badge.img+3

I just want to inform that my issue was resolved. And according to Google Support the problem was that Gemini API had been misused by an unknown person to generate a lot of images. I disabled the Gemini API, revoked the API keys of course and the issue is now resolved. I’ve heard that from more users that the issue is in fact Gemini API in most cases - so if you have that activated, please make sure that you disable it ASAP.


DevDaniel
Forum|alt.badge.img+1
  • Bronze 1
  • May 11, 2026

Yes that was the first thing that I did technically I have resolved it immediately but the cloud console dashboard and my firebase database are still blocked after I have explained everything to detail and next steps that I will take but I can not do that because I cant get to the console. :(


amcastro
  • New Member
  • May 12, 2026

This is very frustrating.

I would pay money to get help on this. 

Yes, there is a paid support option, and it was the only way I managed to get this resolved. I upgraded to Standard Support (which starts at around $29/month).

Hi, where did you do this? I can’t find it and the console is only showing the appeal form. Thanks!


jay_m
  • New Member
  • June 5, 2026

Hi,
I am facing the same issue - account suspended due to hijacked resources. Submitted an appeal but no response since 3 weeks.

I have been trying to upgrade to a standard support plan but I am unable to. 
I tried via the sign up button on support page but I keep on coming across the “request an appeal” page and i also tried contacting the sales rep via chat and they told me they cannot upgrade me to standard plan via chat, they can only upgrade to premium plan which is $15k/month. 

How did you upgrade your plan? Please if you can help me