Main content
FinOps

Why Is My AWS Bill So High? 12 Causes and How to Find Each One

A sudden AWS bill jump usually has a boring cause. Here are twelve common ones, the exact Cost Explorer views that expose them, and a four-step process for finding the culprit fast.

Illustration for “Why Is My AWS Bill So High? 12 Causes and How to Find Each One”

An unexpected AWS invoice is stressful, but the cause is usually mundane and findable in under an hour if you know where to look. This guide gives you a four-step process and twelve of the most common causes, so you can go from "why is my AWS bill so high" to a specific resource and an owner.

Four Steps to Find the Culprit

  1. Pin down when it started. In Cost Explorer, view daily cost for the last 30 to 60 days. A step change on one day points to a deployment or a new resource. A steady climb points to growth or accumulating data.
  2. Group by Service. Compare the spike period with the one before. Find the service that moved most.
  3. Drill into Usage Type, then Linked Account. Usage type names are specific (for example NAT gateway bytes, EBS volume usage or data transfer between regions). Linked account tells you which team to ask.
  4. Find the resource and its owner. Use tags, then CloudTrail to see who created it and when. Decide whether it is legitimate growth, a mistake or an abandoned resource.

A Worked Example

This is an illustration with made-up numbers. Suppose last month's bill is $18,000 against a usual $12,000. Daily cost shows a step up on the 9th that never came back down, so something started then. Grouped by service, EC2-Other (which includes NAT gateways and volumes) is up $4,500 and everything else is flat. Grouped by usage type, NAT gateway bytes explain most of it, and grouped by linked account, one data platform account owns the increase. CloudTrail shows a new nightly job created on the 9th pulling data from S3 through a NAT gateway. The fix is a gateway VPC endpoint for S3, which removes the data processing charge for that traffic. Four views and about thirty minutes took you from a scary number to a one-line change.

12 Common Causes

1. A new or scaled-up workload

The most common and most legitimate cause. Check recent deployments, autoscaling changes and traffic. The fix is a conversation about whether the cost matches the value, not a deletion.

2. NAT gateway traffic

AWS bills NAT gateways at $0.045 per hour plus $0.045 per GB processed (US East, Ohio). A job that pulls large amounts of data through a NAT gateway shows up as a spike in NAT usage types. Gateway VPC endpoints for S3 and DynamoDB carry no hourly or data processing charge.

3. Data transfer between zones or regions

Chatty services spread across Availability Zones, replication jobs and analytics reading from another region produce data transfer charges that can exceed the compute behind them. Filter by data transfer usage types.

4. A forgotten GPU or large instance

An experiment left running over a weekend can cost more than a month of normal workloads. Look for high-priced instance types with low utilization. See why idle GPUs are the new cloud waste.

5. Runaway logging

A debug flag left on, or a retry loop, can write huge volumes to CloudWatch Logs, which bills for ingestion and storage. New log groups keep data forever by default, so storage grows quietly.

6. Public IPv4 addresses

AWS charges $0.005 per hour for each public IPv4 address, in use or idle. A hundred addresses is about $365 a month. Look for the public IPv4 usage type.

7. Orphaned volumes and snapshots

Terminated instances often leave volumes behind, and snapshots outlive their sources. These grow slowly and steadily rather than spiking.

8. Expired free allowances or credits

Free tier allowances and promotional credits expire. A bill that jumps at the same point in the calendar for a new account often traces to this. Check the Billing console's credits and free tier pages.

9. A lapsed or under-used commitment

When a Savings Plan or Reserved Instance expires or your usage shifts away from what it covers, the same workloads move to On-Demand rates and the bill rises with no change in usage. Check coverage and utilization reports.

10. Marketplace subscriptions and support plans

Third-party Marketplace software and some support plans appear as separate line items, and support is often a percentage of usage, so it rises with the bill. Review both.

11. Managed AI and database services

Provisioned throughput, hosted model endpoints and large database instances bill continuously. Check Bedrock, SageMaker and RDS usage types, and see FinOps for AI.

12. An account or credentials you do not recognize

If you see regions you never use or services nobody deployed, treat it as a security incident: rotate access keys, review IAM and CloudTrail, and contact AWS Support.

Stop It Happening Again

  • Set budgets with alerts at several thresholds, and enable Cost Anomaly Detection, so a spike is flagged in days. Our anomaly detection guide covers thresholds and routing.
  • Require owner and environment tags on every resource, so any line item leads to a person.
  • Review commitment coverage monthly.
  • Work the AWS cost optimization checklist on a schedule.

Let Detectors Do the Digging

Varcio flags cost anomalies with root cause and ownership and runs 102 AWS detectors for the idle and orphaned resources above, so you find the cause the day it appears. See AWS cost optimization or talk to our team.

Frequently asked questions

Why did my AWS bill suddenly increase?

The usual causes are a new or scaled-up workload, data transfer or NAT gateway traffic, a forgotten GPU or database, runaway logging, an expired free tier allowance, a lapsed commitment or a change in a managed service. Group cost by service and usage type for the spike period to see which one moved.

How do I find which service is driving my AWS cost?

In Cost Explorer, set the date range to the spike, group by Service, then by Usage Type, then by Linked Account. Compare against the previous period. The usage type name usually tells you exactly what was billed, such as NAT gateway bytes or EBS volume usage.

Can I get alerted before a bill spike?

Yes. Create AWS Budgets with alerts at several thresholds and enable Cost Anomaly Detection so unusual spend is flagged within days instead of at month end. Platforms such as Varcio add anomaly detection with ownership and root-cause context.

What if I cannot explain a charge?

Check the linked account and resource tags first, then CloudTrail for who created the resource and when. If the account itself is unfamiliar or you suspect compromised credentials, rotate keys, review IAM activity and contact AWS Support.

Turn this into savings on your own estate

Connect a cloud account with read-only access and see costed, ranked findings from the first scan — or talk to our FinOps team about a program.