Updated October 3, 2026

Guides · Billing

Why is my AWS bill so high? The usual causes, and how to find them

A surprise AWS bill usually comes down to a few things: resources that kept running after anyone needed them, charges for things that are stopped or detached, and per-GB charges nobody expected. Cost Explorer shows which service and which usage type the money went to. Each cause below lists what to look for there, and links to a guide with the fix.

Start in Cost Explorer

  1. Billing and Cost Management → Cost Explorer. Set the granularity to Monthly, the range to the last three months, and Group by to Service. Find the service that grew.
  2. Filter Service to that one and change Group by to Usage type. Usage types are the units AWS meters. For example, BoxUsage:t2.micro is running hours of t2.micro instances. The usage type usually tells you what kind of resource is costing money. In us-east-1 most usage types have no prefix; in other regions they start with a region code.
  3. Group by Region as well. Spend in a region you don't think you use is worth a look.

With the CLI (each Cost Explorer API request costs $0.01):

aws ce get-cost-and-usage --time-period Start=2026-07-01,End=2026-10-01 \
  --granularity MONTHLY --metrics UnblendedCost \
  --group-by Type=DIMENSION,Key=SERVICE

aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
  --granularity MONTHLY --metrics UnblendedCost UsageQuantity \
  --group-by Type=DIMENSION,Key=USAGE_TYPE

Cost Explorer data can lag by up to 24 hours, so very recent usage may not show yet.

The usual causes, and where they show up

The free checkup looks for every cause in this table.

CauseUsage types to look forGuide
Idle, oversized or older EC2 instancesBoxUsage: followed by the instance typeIdle and oversized EC2
Stopped instances still paying for their disksEBS:VolumeUsageStopped EC2 and RDS
Unattached EBS volumes and old snapshotsEBS:VolumeUsage, EBS:SnapshotUsageUnattached volumes and snapshots
Volumes still on gp2EBS:VolumeUsage.gp2gp2 to gp3
NAT gateway hours and data processingNatGateway-Hours, NatGateway-BytesNAT gateway cost
Idle Elastic IPsPublicIPv4:IdleAddressPublic IPv4 charge
Load balancers with nothing behind themLoadBalancerUsage, LCUUsageIdle load balancers
Idle, oversized or Multi-AZ development databasesInstanceUsage:db., Multi-AZUsage:db.Reduce RDS cost
CloudWatch log groups that never expireTimedStorage-ByteHrs, DataProcessing-BytesCloudWatch Logs cost

The checkup also looks for three things without a guide yet:

Also worth checking

The checkup mentions these as observations, without a savings estimate:

General advice the checkup doesn't cover: to catch the next spike sooner, turn on AWS Cost Anomaly Detection. It uses machine learning models on your Cost Explorer data, runs about three times a day, and alerts you by email or through an Amazon SNS topic. Because Cost Explorer lags, it can take up to 24 hours to detect an anomaly.

The free checkup looks for all of these automatically. A read-only script collects Cost Explorer data, resource settings and 14 days of utilization metrics. By default it scans every region with more than $0.50 of spend last month, plus us-east-1. The analysis runs in your browser and lists each finding with its estimated monthly saving.

Run a free checkup See a sample report

Sources

Prices are AWS on-demand list prices for US East (N. Virginia), checked October 3, 2026. Other regions differ.