Anyone dealt with unauthorized third-party API usage on an inactive project? Looking to learn from your experience

I’m a solo developer, and an inactive side project of mine had unauthorized third-party API usage that Google’s technical team investigated and acknowledged as abuse (they confirmed a 99% duplicate query rate and traffic from a region I’ve never operated in).

I’ve already taken all the recommended steps — removed the keys, disabled the APIs, and shut the project down.

I’m not looking for account-specific support here (I know that goes through official channels). I’m just hoping to learn from others who’ve dealt with a similar situation:

  • If you’ve been through this, how did it ultimately get resolved on your end?
  • What actually helped move things forward?
  • Anything you’d do differently in hindsight?

Just trying to learn from the community’s experience. Thanks!

1 Like