I logged into my Azure account after being away for a while and discovered that my credits had been used up, along with an outstanding bill of roughly $55,000 for August 2026. My legitimate activity was limited to experimenting with AI models, which I later deleted, and I never knowingly ran workloads anywhere near this scale. I found AI Foundry resources I didn't recognize and removed them to stop any additional charges. I suspect the account was compromised because I've noticed suspicious activity on other accounts recently and worry that my email or laptop credentials may have been exposed. I've changed my passwords, frozen my payment cards, and reported the activity to Azure Billing Support as unauthorized. Has anyone dealt with a similar Azure compromise, and what steps helped get unauthorized charges reviewed or reversed? I'm a student with no income, so I cannot pay a bill of this size and want to handle the situation properly.
2 Answers
Keep working directly with Microsoft Billing and clearly document the timeline: when you last had legitimate activity, when you discovered the resources, the resource names and regions, and when you deleted them. Ask them to investigate the activity as an account compromise and review the billing through the abuse or fraud process. Also check the activity logs, subscriptions, IAM assignments, service principals, API keys, and spending limits so you can identify how the resources were created and make sure nothing remains active.
Treat this as a broader credential-security incident, not just a billing issue. Change the Microsoft account password from a trusted device, enable MFA with an authenticator or security key, revoke active sessions and tokens, remove unfamiliar users or roles, rotate any keys, and scan or rebuild the laptop if you suspect it was compromised. Review your email account and other important services too, since an attacker with access to email may be able to reset passwords elsewhere. Continue following up with Microsoft in writing and ask for a temporary hold on collections while the unauthorized-usage investigation is open.

I’ve already reported it to Billing Support and deleted the resources I found. I’m gathering the activity logs and account details now so I can provide a complete timeline.