A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
Urgent Help Needed: Azure Account Compromised, 1M+ INR Charges, Inadequate Support Response
Hello Azure Community,
I'm posting here out of serious concern and frustration after facing a very critical issue with my Azure account and the unresponsive support experience that followed.
đź§ľ Background
- I created my Azure account in 2022 for personal learning and testing purposes.
I have not been using the account regularly, and I hadn't logged in for several months.
- Recently, I was surprised to see a charge of ₹340 INR on my credit card for last billing cycle.
When I logged in to check my billing, I discovered that over 800+ resources had been created under my subscription — without my knowledge.
The Accumulated Cost in the billing section is currently showing ₹10,00,000+ INR (1 million+) — the final bill hasn't been generated yet.
This was honestly a heart attack moment, as I never expected this from a dormant, personal test account.
đź”’ Support Case and Current Situation
- I immediately deleted all resource groups and raised a support ticket and after repeated follow-ups, Azure Support confirmed account compromise.
- They asked me to reset my password and then passed the case to their Security Review Team.
- Since then, I’ve been facing more issues:
- The ticket gets reassigned frequently between engineers as shifts change.
- I keep receiving the same generic response every few hours: “It’s under security review.”
- My ticket has Severity A, but there is no proper update or accountability.
To understand the incident better and potentially protect myself, I requested metadata regarding the unauthorized access — such as:
IP address and region of the login(s) involved in the compromise
How the 800+ resources were created (through Azure Portal, script, or API?)
Whether any login activity emails or alerts were triggered
Unfortunately, Microsoft support denied sharing any of this information, even though they’ve already acknowledged the account was compromised. Also, I did not receive any login activity notification around the date of compromise, which adds to my concern about account and platform-level security.
This is now becoming extremely mentally stressful, especially considering the potential financial impact for something I didn’t even initiate.
âť“ I Need Help With These Questions:
- How can I get a quick resolution on this? Is there any official escalation path, or email IDs of senior support managers or Azure leadership that I can use to bring attention to this? The current support process is not working at all for urgent situations like this.
- Should I file a cybercrime complaint or pursue legal action? Given that account compromise has been acknowledged by Microsoft and the financial impact is substantial, should I: File a case with the Cyber Crime Cell to investigate this further? Consider legal action to protect my financial and personal interests, especially since Microsoft is refusing to provide key metadata and access logs?
- IP Address in Activity Log: In the screenshot below, I highlighted the
ipaddrproperty inside the JSON of an Activity Log entry. Can anyone confirm whose IP address this represents?- Is this the IP address from which the request to create the resource was initiated?
- In the context of account compromise, should this reflect the attacker's originating IP?
Any help, guidance, or escalation contact will be deeply appreciated. I’ve always trusted Azure for learning, but this experience is turning out to be extremely stressful and damaging.
Thank you in advance.