Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

Passwords stored in public Google Doc then showed up in search results

Welcome to PWNED, the weekly column that highlights security failures and offers lessons from them. Our story today is about the misfortune of storing passwords in a public Google Doc, which then appeared in search results.

Pageloot, a company that provides QR codes for marketing, hired a contractor to assist with API integrations. This developer had access to the staging environment's credentials and wanted to view them on multiple devices. Instead of using a secure password manager, the developer stored the credentials in a publicly accessible Google Doc, which anyone could find by simply searching for the company's domain.

A company employee discovered the Google Doc while debugging a non-related issue and found the staging credentials exposed. The search autocomplete even suggested the credentials, making them visible to the world. Once the issue was discovered, the company cut the contractor's access and rotated all exposed credentials. They also established a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools.

Another incident involved a mid-size retailer whose QR codes were directing users to a competitor's website. The retailer found that the culprit was a disgruntled ex-employee who had not been properly offboarded. The ex-employee used their access to redirect all of the retailer's URLs, resulting in lost customers. Both cases demonstrate that proper access control, offboarding procedures, and basic hygiene can prevent such security incidents.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 2 other outlets

Read the original at theregister.com →

More in Tech

More from Thursday 13 August →