← Latest briefing

Technology

Credentials exposed after contractor saves staging passwords in a public Google Doc

A contractor for QR code firm Pageloot set a Google Doc containing credentials to "Anyone with the link," leading to its discovery in search autocomplete.

The short version

  • A developer at Pageloot discovered sensitive staging environment credentials after they appeared in Google Search autocomplete.
  • The exposure was traced back to an external contractor who stored the credentials in a Google Doc and changed its sharing settings to allow public access with the link.
  • Pageloot has since revoked the contractor's access, rotated the credentials, and barred staff from storing passwords in collaboration tools like Google Docs, Slack, and Notion.

Key facts

  • An external contractor hired by QR code provider Pageloot stored staging environment credentials in a Google Doc with sharing set to "Anyone with the link."[Fox News]
  • A developer working for Pageloot discovered the credentials when a company staging hostname and a credential string appeared in Google Search autocomplete.[Fox News]
  • Upon discovering the exposed URL, Pageloot terminated the contractor's access, rotated the compromised credentials, and banned the storage of passwords in collaboration platforms such as Google Docs, Slack, and Notion.[Fox News]
  • Google clarified that Docs are restricted by default, but links to documents configured to allow anyone with the link to view can be indexed by search engine crawlers if published in public locations.[Fox News]
  • Google confirmed that private Workspace content, including Drive and Docs, is not used to train Gemini and other foundational AI models without permission.[Fox News]

What remains uncertain

  • It is not explained how Google Search crawlers originally discovered and indexed the private Google Docs URL to surface it in autocomplete.[Fox News]

Sources