Passwords stored in public Google Doc then showed up in search results

← Back to the feed

Passwords stored in public Google Doc then showed up in search results

The Register · 2 hours ago

A contractor working for QR-code company Pageloot stored staging-server credentials in a publicly accessible Google Doc, which was later indexed by Google and surfaced through search autocomplete. The incident highlights the risks of treating collaboration tools as secure password storage, since exposed staging credentials can still enable attackers to probe systems or gain wider access.

An employee discovered the issue while searching the company’s domain and saw a staging hostname alongside an apparent credential string. Pageloot revoked the contractor’s access, rotated the exposed credentials and prohibited password storage in tools such as Google Docs, Slack and Notion; the article also cites a separate case in which an ex-employee retained access and redirected a retailer’s QR-code links to a competitor.

  • Public Google Doc exposed staging credentials in Google Search.
  • Pageloot revoked access and rotated affected passwords.
  • Secure credential storage and prompt offboarding are essential.

New here? Start with this

Businesses often use separate staging servers to test websites and services before making changes live. These systems can contain copies of company software, data or settings, so the usernames and passwords used to access them can still be valuable to criminals.

Google Docs and other collaboration tools are designed for sharing information, not for keeping secret login details. If a document is made public or shared too widely, search engines may be able to find and display parts of it.

QR codes can direct people to a company’s website, menu or payment page, which makes control of the links important. Companies typically limit access, remove former staff and contractors promptly, and change passwords after an exposure to reduce the chance of unauthorised use.

Software Technology

Read the full article at the source →