Pure speculation, but I wonder if he had gcp service account credentials sitting around his laptop which applied terraform to the wrong project. terraform apply -auto-approve can wipe out a lot of infrastructure in a few seconds.
Not properly setting up and configuring auth could result in long duration of auth tokens, which could be sitting around unknowingly.