services / Google Cloud / Cloud Billing Accounts

A cloud billing account is used to define who pays for a given set of Google Cloud resources and APIs. It is connected to a Google payments profile through which costs are charged.

Removing or updating billing information may render billable Google services or APIs unavailable.


billing.​accounts.​close

It is possible to close an active account. This stops all billable services in linked projects.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​cloud.​google.​com/​billing/​docs/​how-​to/​billing-​access
  • https:​/​/​cloud.​google.​com/​billing/​docs/​reference/​rest/​v1/​billingAccounts
  • https:​/​/​cloud.​google.​com/​billing/​docs/​how-​to/​custom-​roles
  • https:​/​/​cloud.​google.​com/​billing/​docs/​how-​to/​close-​or-​reopen-​billing-​account
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog