- What is cloud consumption fraud?
- Why it matters more than ever
- How cloud consumption fraud is evolving
- What is the financial impact of this type of fraud?
- How can partners strengthen resilience against cloud consumption fraud?
- Why identity verification matters
- Building resilience before it is needed
- Learn more about reducing cloud consumption fraud risk
Growing cloud and AI adoption is creating new opportunities for partners, but it is also creating new opportunities for fraudsters. As organisations consume more cloud services and AI workloads, attackers are finding increasingly sophisticated ways to exploit identities, credentials, and onboarding processes.
What was once primarily a challenge associated with stolen credentials has evolved into a broader issue involving synthetic business identities, AI-generated documentation, and advanced social engineering techniques.
For partners, cloud consumption fraud is more than a security concern. It can affect profitability, customer trust and long-term growth if left unchecked.
What is cloud consumption fraud?
Cloud consumption fraud occurs when individuals or organisations gain unauthorised access to cloud services and consume resources without legitimate approval or payment.
Once access has been gained, attackers can rapidly provision cloud resources, generating significant usage costs before unusual activity is detected.
Why it matters more than ever
Fraud is no longer limited to compromised credentials alone. According to Palo Alto Networks, 90% of breaches involve identity and access control weaknesses.
The statistic highlights an important reality for partners: many incidents stem from preventable weaknesses rather than highly sophisticated attacks.
How cloud consumption fraud is evolving
Three attack vectors are becoming increasingly common:
Compromised accounts
Phishing attacks, stolen credentials or missing multi-factor authentication (MFA) can allow attackers to gain access to legitimate cloud environments and consume resources using trusted identities.
Exposed API keys and credentials
Exposed credentials remain a common entry point for attackers. According to the State of Secrets Sprawl Report 2025, 28.6 million API keys, access tokens and cloud credentials were publicly exposed in a single year, demonstrating how quickly an overlooked secret can become a costly incident.
Fraudulent or impersonated businesses
A growing fraud vector involves stolen or synthetic business identities that appear legitimate during onboarding. These organisations may rapidly provision AI workloads, GPU resources, and other cloud services before abandoning accounts without payment.
As generative AI makes fraudulent documents and identities increasingly convincing, robust verification processes are becoming increasingly important.
What is the financial impact of this type of fraud?
Cloud consumption fraud can result in significant and unexpected costs for partners.
Under reseller agreements, consumption charges resulting from compromised credentials or fraudulent onboarding may remain the partner's responsibility, even when the activity is unauthorised.
The impact can escalate quickly. A single compromised credential can enable attackers to provision cloud resources at scale, generating substantial charges before suspicious activity is identified. By the time unusual consumption is detected, costs may already have accumulated.
That risk is becoming more pronounced as organisations expand their cloud environments and increase their use of AI workloads, GPU resources, and other services capable of consuming significant resources in a short period of time.
Beyond the immediate fiscal impact, cloud consumption fraud can affect customer trust, consume valuable internal resources, and distract teams from growth-focused activities. As a result, prevention, monitoring, and early detection are becoming increasingly important for partners seeking to reduce exposure and protect their cloud investments.
How can partners strengthen resilience against cloud consumption fraud?
While fraud tactics continue to evolve, strong fundamentals remain one of the most effective ways to reduce risk.
Strengthen identity protection
Enable MFA, apply least-privilege access, and regularly review user permissions to help reduce the risk of unauthorised access.
Secure credentials and API keys
Restrict API keys to approved services and IP addresses, avoid storing credentials in source code, rotate secrets regularly and use secure secret-management and scanning tools.
Improve visibility into cloud consumption
Configure budgets, usage alerts, anomaly detection, and regular consumption reviews to identify unexpected activity before costs escalate.
Act on unusual activity
Unexpected consumption spikes and unusual activity should be reviewed immediately. Early investigation can help reduce risk and limit potential financial losses.
Why identity verification matters
Technology can improve visibility into unusual activity, but it cannot verify whether a business is legitimate.
Strong onboarding and end-customer verification processes can help reduce the likelihood of fraudulent organisations gaining access to cloud resources. Independent verification of identities, tax information and supporting documentation is particularly important before provisioning cloud services.
Additional scrutiny may be warranted when you notice:
- Recently registered domains.
- False, look-alike or spoofed email domains that appear similar to legitimate company domains.
- Inconsistent or difficult-to-verify business information.
- Requests to bypass verification procedures.
- Unusually rapid consumption growth.
- Purchasing behaviour that does not align with an end customer's stated business profile.
While these measures can improve visibility into unusual activity, they are not guaranteed to detect, prevent, or mitigate fraud. Partners remain responsible for end-customer due diligence, credential protection, ongoing monitoring, and risk management.
Building resilience before it is needed
The cloud environments partners manage are becoming increasingly interconnected, while AI workloads continue to grow. As a result, fraud tactics are likely to continue evolving.
The partners best positioned to manage cloud consumption fraud are those that embed identity protection, end-customer verification, credential management, and operational discipline into everyday business processes.
Taking a proactive approach can help reduce financial exposure, protect cloud investments, strengthen customer trust, and support sustainable cloud growth.
Learn more about reducing cloud consumption fraud risk
For additional guidance, contact the UK&I Cloud team.
The TD SYNNEX Global Fraud Prevention Team is also available to provide confidential fraud screening and real-time guidance on potentially suspicious customers, transactions, or activities.

