I got an unexpected AWS bill. What do I do now?

6 mins read

Quick answer: Five steps, in this order. Confirm the number on the Bills page, not in an alert email. Find the service and region that is burning in Cost Explorer. Stop or delete it. Open a Billing support case and explain what happened. Then set up an alert so the next one reaches you in hours, not on the invoice.

You opened the bill and the number was wrong. Not a little wrong. Here is what to do in the first 24 hours. Do the steps in order. Each one makes the next one easier.

Is the bill real?

Check before you panic. Open the Billing console and go to Bills. That page is the invoice. An alert email is not. Alerts fire on estimates, and estimates can be wrong.

They were wrong in July 2026. For two days AWS showed inflated cost estimates and fired false budget alerts. Some people saw billions. Nobody was charged.

If the Bills page agrees with the alert, the bill is real. Move to step two.

No more AWS bill surprises

No more AWS bill surprises

Try it today

Try it today

What is burning right now?

Open Cost Explorer. Set the range to the last 14 days, daily. Then group three ways, one after the other.

  1. Group by Service. The line that jumped names your suspect. EC2. Bedrock. CloudWatch. EC2-Other.

  2. Group by Region. Spend in a region you never use is a red flag. Skip to step three and treat it as a leak.

  3. Group by Usage Type. This names the exact thing. NatGateway-Bytes. DataTransfer-Out-Bytes. A GPU instance type you never launch.

Most surprises come from a short list. NAT gateway data. A forgotten environment. Runaway autoscaling. A leaked key. Credits that ran out. The nine common causes are here, with how to spot each one.

Do not spend an hour on this step. You need the service and the region. That is enough to stop it.

How do I stop the bleeding?

Stop the resource first. Understand it later. Every hour it runs costs you money.

  • Instances and databases. Stop them. If you are sure, terminate them. A stopped instance still bills its disks, so delete volumes and snapshots you do not need.

  • Jobs and functions. Disable the trigger. Set the concurrency to zero. Kill the queue that feeds it.

  • A region you never use. Assume someone else is in your account. Rotate every access key first. Then terminate what you find. Check CloudTrail, the log of every API call on your account, for who created it.

Take screenshots of what you found and what you did. You will need them in the next step.

Should I talk to AWS?

Yes. Today. Open the Support Center in the console and create a case. Pick Account and billing. This works on every support plan, including the basic one.

Say what happened in plain words. What ran, for how long, what it cost. Say what you fixed and when. Attach the screenshots. Ask if they can review the charge.

AWS sometimes waives or reduces a first-time accidental charge. One developer got Free Tier overage waived after explaining the mistake. That is a courtesy, not a rule. You will not know until you ask. And a case filed the same day reads better than one filed after the due date.

If someone broke into your account, say so in the case. That is a different track and AWS handles it differently.

How do I make sure this never happens again?

This is the step people skip. The bill is paid, the instance is gone, and life moves on. Then it happens again.

AWS gives you three built-in options. All three need you to set them up. None of them set themselves up.

  • AWS Budgets. You pick a monthly number and a threshold. It updates up to three times a day, 8 to 12 hours apart. It fires only when spend crosses the line you guessed.

  • Cost Anomaly Detection. You create a monitor and a subscription. It starts working within 24 hours and checks about three times a day, on data that is 12 to 48 hours old.

  • CloudWatch billing alarm. You turn on "Receive CloudWatch Billing Alerts", switch to the N. Virginia region (us-east-1), create an alarm on estimated charges, and wire it to an SNS topic, AWS's notification relay, and then to email.

They come with your account and they help. They are also slow, and every threshold is yours to pick and yours to re-tune. Slack takes a separate setup. AWS Budgets versus spike detection is its own article.

Nobody at AWS gets paged when your bill doubles. That is not a dig. It is how the incentives sit. The alarm has to be yours.

How does watchmy.cloud help here?

Connect AWS. Read-only billing access. No keys. No access to what you run. One CloudFormation template, about two minutes.

Send it where work happens. Slack for fast triage. Jira for follow-up. API when you want control.

Stop worrying about it. We watch AWS spend for you, so you don't have to keep checking it.

After the connect it runs automagically. Two rules are on from day one. One fires when a day runs 30% above your own 7-day average. One fires when an hour costs three times what that hour normally costs. One dial, 1 to 5, tunes both. We check every hour. A flat $49 a month. How it works, and who we are.

Watching AWS spend is our full-time job. You focus on your product and sleep well.

FAQ

Will AWS refund an unexpected bill? Sometimes, for a first accidental charge, if you ask through a Billing support case. It is a courtesy, not a rule. Explain what happened, what you fixed, and when. Ask the same day you find the charge.

How do I contact AWS about a billing problem? Open the Support Center in the AWS console and create a case under Account and billing. This is available on every support plan, including the basic one. Attach screenshots of the charge and what you fixed.

Why did I get an AWS bill for a service I never used? Check the region first. Spend in a region you never use most often means a leaked access key. Rotate every key, terminate what you find, check CloudTrail, and tell AWS in your support case that the account may be compromised.

Can I set a hard spending limit on AWS? No. AWS has no hard cap that stops all spending. AWS Budgets with actions can stop some EC2 and RDS resources when a threshold is crossed. The first two action-enabled budgets come with your account. After that each one costs $0.10 a day.

How fast will I know about the next spike? With the built-in tools, the same day or the next one. They check a few times a day on data that lags 12 to 48 hours. With watchmy.cloud we check every hour. With hourly granularity on in Cost Explorer, the alert lands about an hour after the spike shows up in the data.

Does a stopped EC2 instance still cost money? Yes, a little. The instance itself stops billing, but its EBS volumes and snapshots keep billing until you delete them. Elastic IPs on a stopped instance bill too.

See it before you connect anything: live demo, no sign-up.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.