Main content
FinOps

Hidden AWS Savings Opportunities: 12 Places Your Bill Is Leaking in 2026

NAT gateways, idle public IPs, gp2 volumes, forgotten snapshots, log retention and more. Twelve places AWS bills quietly leak money, with the pricing facts to size each one.

Illustration for “Hidden AWS Savings Opportunities: 12 Places Your Bill Is Leaking in 2026”

The expensive AWS mistakes are rarely dramatic. They are small, recurring charges for things nobody is looking at, and they add up. This list covers twelve places we see AWS bills leak, with the public pricing facts you need to size each one. Prices are taken from AWS's own pricing pages and vary by region, so confirm yours before you act.

1. NAT Gateways

A NAT gateway costs $0.045 per hour plus $0.045 per GB processed (US East, Ohio), and each partial hour is billed as a full hour. That is about $33 a month per gateway before any traffic. Push 1,000 GB through it in a month and you add $45. Two common fixes: use gateway VPC endpoints for S3 and DynamoDB, which AWS lists with no hourly or data processing charge, so that traffic bypasses the NAT entirely; and avoid one gateway per environment where one shared design would do.

2. Idle Public IPv4 Addresses

AWS charges $0.005 per hour for every public IPv4 address, in use or idle. That is about $3.65 a month each. One address is nothing. A hundred forgotten Elastic IPs and public-facing instances is $365 a month for no value. Release unattached Elastic IPs and ask whether each public address really needs to be public.

3. gp2 Volumes That Should Be gp3

AWS lists gp3 at up to 20% lower price per GB than gp2: $0.08 versus $0.10 per GB-month in US East, with a baseline of 3,000 IOPS and 125 MB/s at any size. On 10,000 GB of gp2, that is $1,000 a month versus $800, or $200 saved every month, and the change is made online. Check any workload that depends on gp2 burst behavior or needs more than the gp3 baseline, but for most volumes it is free money.

4. Unattached Volumes and Orphaned Snapshots

Terminating an instance does not always delete its volumes, and snapshots outlive the volumes they came from. Both bill by the GB-month. Review unattached volumes older than a few weeks and snapshots whose source volume or AMI no longer exists, and use lifecycle policies to expire the rest automatically.

5. Idle Load Balancers

Load balancers bill by the hour whether or not they carry traffic, and they are easy to leave behind after a decommissioned service. Look for load balancers with no healthy targets or near-zero request counts over a few weeks.

6. CloudWatch Log Groups With No Retention

New log groups keep data indefinitely by default. A noisy service can generate a surprising amount of stored data over a year. Set a retention period on every log group, and ship long-term logs to cheaper storage if you need them.

7. S3 Storage Classes and Lifecycle Rules

Data that is rarely read does not need to sit in the standard storage class. Lifecycle rules and S3 Intelligent-Tiering move objects to cheaper tiers automatically. Also clean up incomplete multipart uploads and old object versions in versioned buckets, which keep billing quietly.

8. Cross-AZ and Cross-Region Data Transfer

Traffic between Availability Zones and between regions is charged. Chatty microservices spread across zones, replication jobs and analytics that pull data from a distant region can all produce a data transfer line larger than the compute behind them. Look at the data transfer line items by usage type to find the biggest sources.

9. Always-On Non-Production Environments

Development, test and staging environments typically need to run during working hours, but they often run around the clock. Scheduling them to stop at night and on weekends removes well over half of their running hours. Our 30-day cloud waste plan includes a rollout.

10. Oversized EC2 and RDS Instances

Instances sized for a peak that never arrived are one of the largest sources of waste. AWS Compute Optimizer and your monitoring data show sustained low CPU and memory use. Test downsizing in non-production first, and review database storage and Provisioned IOPS settings at the same time.

11. Graviton Instead of x86

AWS states that Graviton-based instances cost up to 20% less than comparable x86-based EC2 instances. Many Linux workloads move with little change, and the option exists across EC2, RDS, ElastiCache and Lambda. Treat it as a project with testing, not a flag flip, and prioritize your largest steady workloads.

12. Steady Workloads Left on On-Demand

Once waste is removed, commit to what remains. AWS lists savings of up to 66% for Compute Savings Plans and up to 72% for EC2 Instance Savings Plans versus On-Demand, with one- or three-year terms. Those are maximums, not averages, and the actual rate depends on term, payment option and instance family. Commit last, and size to your steady baseline. Our commitment guide explains how.

Where to Start

Opportunity Effort Risk
gp2 to gp3, release idle IPs, add log retentionLowLow
Delete unattached volumes, old snapshots, idle load balancersLowLow with owner sign-off
Schedule non-production, S3 lifecycle rules, VPC endpointsLow to mediumLow
Rightsize EC2 and RDS, review data transferMediumMedium, test first
Graviton migration, then Savings PlansMedium to highMedium, commit last

Find These Automatically

You can work through this list by hand with Cost Explorer and Compute Optimizer, and the native tools are a fine start. The problem is repetition: new waste appears every week across every account. Varcio's AWS cost optimization runs 102 AWS detectors continuously, covering unused Elastic IPs, unattached EBS volumes, EC2 and RDS underutilization, old snapshots and network waste, with costed findings and approval-gated fixes. Talk to our team for a baseline of your own account.

Frequently asked questions

What are the biggest hidden AWS costs?

Common leaks are NAT gateway data processing, idle public IPv4 addresses, gp2 volumes that should be gp3, unattached volumes and old snapshots, idle load balancers, CloudWatch log groups with no retention, cross-AZ data transfer, oversized databases, always-on non-production environments and uncovered steady workloads that would be cheaper on Savings Plans.

How much does an AWS NAT gateway cost?

AWS lists NAT gateways at $0.045 per hour plus $0.045 per GB processed in US East (Ohio), billed whether or not traffic flows. That is about $33 a month per gateway before data charges. Prices vary by region, so check the AWS VPC pricing page for yours.

Is gp3 cheaper than gp2?

Yes. AWS lists gp3 at up to 20% lower price per GB than gp2 ($0.08 versus $0.10 per GB-month in US East), with a baseline of 3,000 IOPS and 125 MB/s at any size. Migrating is an online change with no downtime.

How can I find hidden AWS savings automatically?

Use native tools such as Cost Explorer, Compute Optimizer and Trusted Advisor for a starting list, and a cost platform with continuous detectors for coverage across accounts. Varcio runs 102 AWS-specific detectors, including unused Elastic IPs, unattached EBS volumes, EC2 and RDS underutilization, old snapshots and network waste.

Turn this into savings on your own estate

Connect a cloud account with read-only access and see costed, ranked findings from the first scan — or talk to our FinOps team about a program.