Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

2026-05-22T08:51:45Z0e54b648c378ff615c75cc80bf0c528baf0bcb9f94c6a7ca973d71af6756bb2b
ai-assisted-exploitationandroid-malwareapi-keysbanana-ratbanking-fraudbigquerycredential-exposureeuropolfileless-malwaregcpgeminigithub-breachgoogle-api-keysincident-responsemapsmshtaphishingpremium-sms-fraudransomwareremote-access-toolssecurity-awarenesssupply-chainverizon-DBIRvpn-seizurevs-code-extension

What happened

Multiple high-impact cyber developments: deleted Google API keys can remain active up to ~23 minutes, risking GCP assets (Gemini, BigQuery, Maps); Europol seized 'First VPN' used by ransomware gangs and arrested its administrator, yielding user data; TeamPCP stole ~3,800 private GitHub repositories via a malicious VS Code extension and is selling the haul; MSHTA (legacy IE tool) is being abused in fileless Windows attacks; a global Android campaign has been secretly subscribing victims to premium SMS services; Banana RAT malware targets customers of 16 Brazilian banks via fake invoices/QR-fraq

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
0e54b648c378ff615c75cc80bf0c528baf0bcb9f94c6a7ca973d71af6756bb2b
Enrichment time
2026-05-22T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.