0%

Preparing the page

Why Is My AWS Bill So High? 9 Common Causes and How to Fix Them

AWS bill higher than expected? Here are the 9 most common causes, from idle EC2 to NAT Gateway and data transfer charges, and how to fix each one.

Irfan Harees

Irfan Harees · Senior Program Manager – Research, Marketing & Strategy

· 6 min read

Share
An AWS bill with nine small glowing leaks, five labelled EC2 instances, NAT Gateway, Data transfer, EBS snapshots and CloudWatch Logs, dripping blue light into a pool below.

You opened the AWS billing console and the number made you wince. You did not launch anything big. Nobody remembers changing anything. Yet the bill is up 20, 30 or 40 percent.

High AWS bills are rarely caused by one dramatic mistake. They are usually caused by many small, quiet leaks. Here are the nine we find most often when we review AWS accounts, and what to do about each.

High AWS bills are rarely caused by one dramatic mistake.

How do I find out what is driving my AWS bill?

Start with AWS Cost Explorer. Group costs by Service, then by Usage Type, and compare the last three months. That shows you which service grew and exactly which usage type (for example, DataTransfer-Out-Bytes or NatGateway-Bytes) is responsible.

Stacked monthly bars for July, August and September grouped by AWS usage type; total spend rises 30%, driven mostly by NatGateway-Bytes, which grows from $2.0K to $11.2K.
Cost Explorer grouped by usage type over three months: the NatGateway-Bytes line is what grew. Figures are illustrative.

If costs are spread across many accounts, use AWS Organizations consolidated billing and the Cost and Usage Report (CUR) for line-item detail. Without tags, you will see *what* is expensive but not *who* owns it, so fix tagging early.

The 9 most common causes of a high AWS bill

1. Idle and oversized EC2 instances

Instances launched for a test, a demo or a migration often keep running for months. Others are sized for peak load that never comes. Use AWS Compute Optimizer and CloudWatch CPU and memory metrics to find instances running consistently below 20–30% utilisation, then downsize or stop them.

2. No Savings Plans or Reserved Instances

Running steady workloads on On-Demand pricing is the most expensive way to use AWS. Compute Savings Plans and Reserved Instances offer significant discounts for a 1- or 3-year commitment. Compare options in our guide to Reserved Instances vs Savings Plans.

3. Unattached EBS volumes and old snapshots

When an instance is terminated, its EBS volumes are not always deleted. Snapshots also pile up from automated backups with no retention policy. Both are billed every month, silently.

4. NAT Gateway data processing charges

NAT Gateways charge per hour and per gigabyte processed. Workloads in private subnets that pull large volumes from S3 or ECR through a NAT Gateway can generate large bills. VPC gateway endpoints for S3 and DynamoDB route that traffic privately and avoid the NAT processing fee.

Diagram: traffic from a private subnet reaches Amazon S3 by two routes, through a NAT Gateway billed per hour and per GB processed, or through a VPC gateway endpoint with no NAT processing fee.
The same private-subnet traffic to S3 through a NAT Gateway (metered per hour and per GB) or a VPC gateway endpoint (no NAT processing fee). Gateway endpoints cover S3 and DynamoDB.

5. Data transfer between regions and to the internet

Data leaving AWS, and data moving between Availability Zones or Regions, is charged. Chatty microservices spread across AZs, cross-region replication and unoptimised CDN setups all add up. Use CloudFront for public content and keep high-traffic services in the same AZ where resilience allows.

6. Storage on the wrong tier

S3 Standard for data nobody reads, and gp2 volumes that could be gp3, both cost more than necessary. Use S3 Intelligent-Tiering or lifecycle rules to move cold data, and migrate gp2 volumes to gp3, which is cheaper per GB and lets you provision performance separately.

7. CloudWatch Logs with no retention

By default, CloudWatch Log Groups keep data forever. Verbose application logs at scale can become one of the fastest-growing costs in an account. Set retention periods and reduce debug-level logging in production.

8. Non-production environments running 24/7

Development, QA and staging environments rarely need to run nights and weekends. Scheduling them to stop outside working hours can cut their compute cost by more than half.

9. Forgotten managed services

Unused RDS instances, idle load balancers, Elastic IPs not attached to running instances, and abandoned OpenSearch domains are all billed whether anyone uses them or not.

Quick-reference: cause, signal and fix

CauseWhere you see itFix
Idle/oversized EC2Compute Optimizer, low CPURightsize, stop, schedule
No commitmentsHigh On-Demand shareSavings Plans after rightsizing
Orphaned EBS/snapshotsEC2 > Volumes "available"Delete, set retention
NAT GatewayNatGateway-Bytes usage typeVPC endpoints
Data transferDataTransfer usage typesCloudFront, AZ affinity
Wrong storage tierS3 Standard, gp2Lifecycle rules, gp3
Log retentionCloudWatch Logs growthRetention policies
24/7 non-prodSteady non-prod spendInstance Scheduler
Forgotten servicesLow-traffic RDS, ELB, EIPsDecommission

How do I stop my AWS bill from rising again?

One cleanup is not enough. Costs creep back unless you change how decisions are made:

  1. Enforce tagging with AWS Organizations tag policies or Service Control Policies.
  2. Turn on AWS Cost Anomaly Detection and route alerts to the owning team, not a shared inbox.
  3. Set AWS Budgets per team or product with alerts at 80% and 100%.
  4. Review weekly. Fifteen minutes per team, looking at top movers.
  5. Show engineers the cost of what they build, in the tools they already use.

These are the foundations of a FinOps practice. Our guide What Is FinOps? explains the full model.

How Crozaint approaches high AWS bills

Crozaint is an AWS Select Consulting Partner. Our FinOps engagements begin by consolidating billing data, often across many accounts, into one view. From there, our AI Cost Optimization Agent monitors spend continuously and flags anomalies, idle resources and rightsizing opportunities as they appear, rather than at month-end.

Malabar Gold & Diamonds came to us with a complex AWS billing structure. Their IT Manager described Crozaint as "really helpful in consolidating our complex AWS billing structure." Across our FinOps engagements, clients see an average 27% reduction in cloud spend within 60–90 days.

Common mistakes to avoid

  • Buying 3-year Reserved Instances before rightsizing
  • Deleting snapshots without checking backup and compliance requirements
  • Sending all cost alerts to one person who cannot act on them
  • Optimising one big account while dozens of small ones grow unnoticed
  • Treating data transfer as "unavoidable" without checking architecture

Conclusion

A high AWS bill is almost always a collection of fixable leaks. Find them with Cost Explorer, fix the obvious ones this week, and put tagging, anomaly alerts and reviews in place so they do not return.

Want a second pair of eyes on your AWS bill? Talk through your cloud bill with a senior Crozaint engineer in a 30-minute call.

Frequently Asked Questions

Why did my AWS bill suddenly increase?

Sudden increases usually come from new resources left running, a traffic spike, a change in data transfer patterns, log volume growth or an expired Reserved Instance. Use Cost Explorer grouped by service and usage type, comparing day by day, to pinpoint the date and source of the jump.

What is the fastest way to reduce AWS costs?

The fastest wins are stopping idle instances, deleting unattached EBS volumes, scheduling non-production environments, setting log retention and adding S3 and DynamoDB VPC endpoints. These require no commitments and can often be done within days. Savings Plans come next, once usage is stable.

Is AWS Cost Explorer enough to manage costs?

Cost Explorer is good for investigation, but on its own it is reactive. Effective cost management also needs consistent tagging, anomaly alerts routed to owners, budgets per team and a regular review cadence. Multi-cloud organisations usually need a unified view across providers too.

How much can I save on my AWS bill?

It depends on your starting point. Accounts with no commitments, no tagging and long-running non-production environments typically have the most to gain. Across Crozaint FinOps engagements, the average reduction in cloud spend is 27% within the engagement window.

Why are NAT Gateway charges so high?

NAT Gateways charge for every gigabyte they process in addition to an hourly fee. Private workloads pulling large amounts of data from S3, ECR or the internet through a NAT Gateway can generate large charges. Gateway VPC endpoints for S3 and DynamoDB avoid this processing fee.

Irfan Harees

Written by

Irfan Harees

Senior Program Manager – Research, Marketing & Strategy · 10 articles

Irfan runs the growth side of Crozaint — how the offering is shaped, how it reaches the market, and how the team behind it is built. An IIT Roorkee MBA with a Six Sigma habit, he brings a process-first, numbers-first discipline to what most companies treat as instinct: positioning, funnels, hiring.

JosephReviewed for technical accuracy by Joseph, Cloud Consulting.

After the reading

Reading About FinOps Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Irfan Harees

Talk to Irfan

Wrote this article · Senior Program Manager – Research, Marketing & Strategy

Thirty minutes on your estate. Irfan looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.