ElevenLabs customer alleges unauthorized account use drove a $39,000 usage spike
JayJay P. says two separate company accounts showed abnormal activity, including one that typically spent $100-$200 a month.
By Ryan Merket · Published
Primary source: X
Why it matters
As ElevenLabs sells metered audio tools and business agents, customers need account-level controls and fast incident handling. JayJay's claims remain unverified and do not establish a breach of ElevenLabs' systems.

JayJay P. says unauthorized users drove about $39,000 in abnormal usage on one company's ElevenLabs account over seven to 14 days, then similar activity appeared on a second company's account. The allegations, posted on October 5th, raise questions about account access and the speed of incident response, but do not establish that ElevenLabs' own systems were breached.
In the X post, JayJay said the first company usually spent $100-$200 per month and had reported the issue weeks earlier without receiving what JayJay considered a proper investigation. A finance team at the second company, described as a separate business, detected similar activity within an hour. JayJay asked for an introduction to an ElevenLabs account manager or someone on its security or trust-and-safety team, and said evidence and a timeline could be shared privately.

The $39,000 figure is JayJay's estimate of abnormal usage, not an independently verified loss or a confirmed charge. The post does not explain how either account was accessed, whether credentials or API keys were exposed, or whether the usage came from a flaw in ElevenLabs' systems. Unauthorized use of an account and a breach of the service provider's infrastructure are different events; the public account does not resolve which, if either, occurred here.
The allegations come as ElevenLabs expands beyond text-to-speech into business deployments through ElevenAgents, its voice and chat agent product. In February, co-founders Mati Staniszewski and Piotr Dąbkowski said the company had raised a $500 million Series D at an $11 billion valuation, with the proceeds supporting enterprise adoption and product development. On September 30th, ElevenLabs said a $300 million employee tender offer valued it at $22 billion. Those figures are company announcements; the valuation context does not substantiate JayJay's account.
For a metered AI service, a compromised credential or an unbounded integration can turn routine product usage into a large bill quickly. ElevenLabs' current developer documentation describes API-key controls including endpoint restrictions, credit quotas and IP allowlisting. Its workspace documentation also describes billing-group limits that can stop requests once a configured quota is reached. These controls can constrain usage when configured; their existence does not show whether they were enabled on the accounts JayJay describes or whether they would have prevented the reported activity.
ElevenLabs' documentation also lets workspace administrators inspect usage by user, group, product or API key. JayJay's account of the second incident points to the value of that monitoring: the finance team reportedly noticed the unusual activity within an hour. The first account's reported seven-to-14-day window presents a different operational problem, regardless of how access was obtained. The post does not say whether either company used usage limits or what alerts were available to its administrators at the time.
For customers evaluating ElevenLabs for production work, account permissions, usage visibility and a clear way to resolve suspected misuse are part of the service, alongside model quality and latency. ElevenLabs says its platform serves enterprises as well as developers and creators, and has promoted voice agents for customer support and other business operations.