My Azure startup account had approximately $10,000 in promotional credits. While I was hospitalized, I received unexpected one-time-password emails but did not act on them. About 9–13 days later, I discovered roughly $550,000 (around ₹5 crore) in charges, apparently for unauthorized Claude usage purchased through Azure Marketplace. I did not create or approve these workloads. I have disabled the resources and contacted Azure Support, but the initial representative said they had not yet confirmed fraudulent activity. I am a college student with only my name and a debit card connected to the account, and I cannot pay anything close to this amount. Has anyone dealt with unauthorized Azure Marketplace charges on this scale? What billing, fraud, security, or Marketplace teams should I contact? Could Microsoft or the Marketplace provider waive charges after an investigation, and what evidence should I preserve?
5 Answers
Because the usage was purchased through Azure Marketplace, Azure may need to coordinate with the publisher or provider involved. Contact Azure Billing and Marketplace support, explain that the usage was unauthorized, and ask which party is responsible for reviewing or reversing the charges. Keep every provider invoice and usage breakdown, since the billing path may matter.
At this amount, do not rely only on ordinary chat support or informal promises. Keep a written timeline and copies of all correspondence, and consider consulting a qualified lawyer or consumer and technology-fraud adviser in your jurisdiction. Whether you are legally responsible, whether a payment can be disputed, and whether court action is possible depend on the account terms, the investigation, and local law.
Open an urgent Azure billing and security support case and clearly describe the suspected account compromise, the unexpected OTP messages, your hospitalization, the exact timeline, and the resources or Marketplace purchases you did not authorize. Ask for the case to be escalated to the fraud or account-compromise team. Preserve everything: Activity Logs, sign-in and audit logs, resource IDs, deployment timestamps, usage records, invoices, OTP emails, support case numbers, and proof of when you were hospitalized. Do not delete evidence before exporting it.
Once the account is secured, set spending alerts, budgets, quotas, and resource policies wherever the platform supports them. Those controls may not automatically cancel a bill, but they can reduce the chance that a compromised account accumulates another large balance. Also review why the unexpected OTPs were generated, since they may help establish when someone tried to access the account.
Immediately secure the account: change the password, enforce strong MFA, revoke unfamiliar sessions, rotate API keys and secrets, review owners and RBAC assignments, inspect service principals, and remove anything you do not recognize. Check whether any deployments are still active and stop them, but export logs first if possible. Also contact your bank about the attached debit card and ask what protections or payment holds are available.
Do not assume stopping the resources resolves the billing issue. It only prevents additional usage; the existing charges still need a documented fraud and billing review.

The first support representative may not have authority to decide whether the charges are fraudulent. Keep the case open and request a formal billing investigation rather than relying on the initial response.