At Google Cloud, securing your data and business systems is our foundational commitment. We empower our customers with the tools, governance, and infrastructure needed to securely deploy workloads and maintain long-term trust.
We approach security from a shared fate model, and we continuously work to proactively identify and mitigate potential threats before they can compromise your data and misuse your infrastructure.
Understanding the risk: How bad actors attempt to exploit cloud workloads
Hyperscale cloud platforms like Google Cloud offer massive compute capacity, high-speed networking, and cutting-edge AI engines, but these same core strengths also make us high-value targets for malicious actors seeking service disruption, financial gain, or exploit cloud resources.
By tracking active adversary techniques, Google’s specialist security teams actively monitor and defend across several areas.
-
AI workload exploitation: As organizations rapidly adopt AI tools and systems, including Gemini Enterprise Agent Platform, threat actors target unsecured API keys and leaked access tokens. Common attack patterns include using stolen credentials for unauthorized distillation attacks and reselling access tokens on third-party marketplaces. We track consumption rates, account standing, and access context to catch these anomalies early.
-
Cryptocurrency mining: Malicious actors often use stolen credentials to spin up virtual machines (VM) for illicit cryptomining. While Google Cloud respects customer privacy and does not inspect internal VM processes, we can accurately infer mining activity by analyzing infrastructure telemetry — such as distinctive CPU and memory utilization spikes and rapid VM creation rates.
-
Exfiltrated credentials and supply chain attacks: Developers occasionally commit secrets and API keys to public source repositories where automated scrapers harvest them in seconds. Exposed credentials also stem from supply chain attacks against local development environments or managed cloud workloads.
-
Account takeover (ATO): Adversary-in-the-middle (AITM) techniques — such as sophisticated phishing and session cookie theft — can grant unauthorized users administrative control. Once inside, adversaries establish persistence, move laterally, and execute downstream abuse like resource hijacking or data exfiltration.
Without proper containment, these attacks can lead to operational disruptions, compromised system integrity, and unchecked resource misuse — such as runaway costs — creating substantial friction for impacted users.
Mitigating risks: Tailored containment in action
Detecting a threat is only half the battle; maintaining business continuity by containing it without interrupting your legitimate operations is critical. Google Cloud deploys tailored mitigation strategies based on the nature of the threat.
-
Granular containment and throttling: When anomalous traffic indicates AI abuse or cryptomining, we apply targeted throttling measures. This isolates malicious activity while preserving legitimate corporate traffic.
-
Collaborative triage for complex workloads: In AI environments, malicious API calls are often interlaced with critical business operations. In these scenarios, our Cloud Abuse and Cloud Support teams collaborate directly to isolate and inspect specific traffic vectors.
-
Localized identity isolation: To prevent lateral movement, localized containment protocols can be systematically applied across compromised user identities and Google Workspace domains.
-
Targeted suspensions as a last resort: Our primary objective is to enforce containment at the most granular resource level possible. However, if platform integrity or customer financial exposure is severely threatened, we may temporarily suspend specific projects, backed by a clear appeal process.
Additionally, to stop attacks at the root, Google actively partners with public repository hosters through initiatives like GitHub Secret Scanning to catch exposed credentials immediately and trigger proactive warnings before exploitation occurs.
Communicating risk: Proactive transparency and log visibility
During a security event, time-to-awareness is everything. We provide a robust suite of tools and channels to ensure your key security stakeholders receives actionable visibility:
-
Cloud Abuse Event Logging: Provides a 30-day window into security and abuse notifications with resource-level granularity. These logs can be ingested directly into your SIEM product for automated orchestration and response.
-
Proactive support cases and abuse notifications: When critical abuse is detected, automated email notifications and high-touch support cases are generated to open an immediate channel for resolution and best-practice sharing.
-
Cloud Audit Logging and anomaly spending alerts: Audit logs monitor unexpected resource changes that point to an ATO, while automated billing alerts notify key stakeholders of sudden spend spikes driven by compromised workloads.
-
Essential Contacts: To ensure notifications reach the right people instantly, Google Cloud allows you to maintain a dedicated directory of designated contacts across security, billing, and operations.
Customer action plan: Hardening your environment
We handle the security of the underlying infrastructure, yet your organization remains resilient only through proactive hygiene on your side of our shared fate partnership.
To minimize risk exposure across your user accounts, service accounts, and API keys, we recommend implementing these foundational defenses.
-
Mandatory identity protection: Enforce multi-factor authentication (MFA) and 2-Step Verification (2SV) across all user accounts and Google Workspace domains without exception to prevent AITM cookie theft and phishing attacks. Ensure that you use Device Bound Session Credentials (DBSC) for your Google Workspace accounts to bind a user’s session to their specific device.
-
Secure service accounts and API keys: Treat keys and tokens as top-tier secrets. Never embed API keys in source code or public repositories. Use keyless authentication where possible, rotate keys regularly, and follow strict governance for service account management.
-
Enforce least privilege and perimeter defense: Use Identity and Access Management (IAM), VPC Service Controls (VPC-SC), and Context-Aware Access (CAA) to restrict access so identities only have the exact permissions required for their specific function.
-
Configure Essential Contacts and billing alerts: Set up detailed billing alerts to identify unauthorized spending before costs rise, and conduct quarterly reviews to keep your Essential Contacts directory current.
-
Regular resource hygiene: Conduct periodic audits of your organization to identify and decommission unused resources, legacy billing accounts, and dormant user accounts. Pay special attention to groups or service accounts with elevated permissions to ensure your attack surface remains as small as possible.
Continuous vigilance together
Google continuously monitors platform health to detect anomalous usage patterns before they impact your workloads.
Ultimately, maintaining a secure environment is a partnership built on shared fate. While we take every precaution to prevent bad actors from gaining a foothold, protecting your organization requires equal dedication on your end. By applying robust access controls, staying vigilant, and adopting security best practices, together we can keep your workloads secure and resilient.
Explore key resources to harden your environment: