PlaybooksUnexpected cloud bill
Moneycritical35 minutes to prepare

Unexpected cloud bill

Cloud, AI, storage, bandwidth, or API spending rises far beyond the expected amount.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Stop new spend without destroying evidence or production, then allocate every cost to legitimate demand, waste, misconfiguration, or abuse.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Export cost and usage by account, service, region, resource, tag, operation, tenant, hour, and pricing dimension.
  • Preserve audit logs, deployments, autoscaling, API use, access keys, new resources, data transfer, logs, snapshots, and support case IDs.
  • Compare billing to traffic, business volume, security alerts, quotas, budgets, commitments, and the last normal period.

Decisions that change the response

QuestionAct whenAction
Disable resources?Ownership and customer impact are known or spend is clearly malicious.Quarantine suspicious identities and stop bounded resources; protect logs and snapshots before deletion.
Request a billing adjustment?Cause and containment are documented and provider policy may apply.Open a case promptly with exact resource IDs and times; do not assume credits.

Proof that recovery worked

  • Hourly spend returns to an explained baseline and no unowned resource, region, account, or data transfer remains.
  • Security review accounts for credentials and actions behind suspicious consumption.
  • Invoices, credits, commitments, taxes, and internal allocation reconcile with the provider.

Controls to put in place

  • Use budgets, anomaly alerts, service quotas, per-environment accounts, and mandatory ownership tags.
  • Restrict expensive services and regions; expire test resources automatically.
  • Review unit cost per customer action and rehearse safe spend containment.
Tabletop drill

Create a tagged sandbox cost spike. Detect it from an hourly alert, identify its actor and resource, quarantine it, estimate invoice impact, and prepare a provider case.

Escalate when

Contact provider billing and security support when compromise, cryptomining, account takeover, or a material invoice is possible; involve finance before changing commitments.

What this means

The cause may be legitimate growth, a loop, abusive traffic, leaked credentials, forgotten resources, or pricing behavior. Turning off everything can destroy evidence and customer data.

Warning signs

  • Budget or anomaly alerts show a sudden daily or hourly increase.
  • Spend rises without matching users, revenue, or planned work.
  • One service, region, model, resource, or usage type dominates.
  • New resources or credentials appear in audit logs.

Recover now

First 15 minutes

  1. Break cost down by service, account, region, resource, and usage type.
  2. Preserve billing, usage, identity, and audit evidence.
  3. Cap or stop the specific runaway consumer safely.
  4. Revoke exposed credentials and contain abusive traffic when indicated.

Today

  1. Remove orphaned resources, retry loops, public workloads, or unintended scale.
  2. Contact provider billing support with exact anomaly times and actions.
  3. Estimate committed cost and cash-flow impact.
  4. Add per-service budgets, quotas, and cost-to-business metrics.

Verify recovery

  • Hourly cost returns to an explainable range.
  • No unauthorized resources or usage continue.
  • Critical data and services remain intact.
  • Alerts detect a repeat before material loss.

Prepare now

Access

  • Billing and security investigation access is available to two people.

Backups and evidence

  • Detailed billing and audit logs have useful retention.

Contacts and ownership

  • Every major cost center has an owner and normal range.

Practice

  • A cost anomaly can be traced to a resource and contained.

Common mistakes

  • Deleting resources before preserving evidence.
  • Setting only a monthly alert.
  • Assuming every spike is provider error.

Sources

Last reviewed July 19, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.