Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
Welcome to PWNED, the weekly column that highlights security failures and offers lessons from them. Our story today is about the misfortune of storing passwords in a public Google Doc, which then appeared in search results.
Pageloot, a company that provides QR codes for marketing, hired a contractor to assist with API integrations. This developer had access to the staging environment's credentials and wanted to view them on multiple devices. Instead of using a secure password manager, the developer stored the credentials in a publicly accessible Google Doc, which anyone could find by simply searching for the company's domain.
A company employee discovered the Google Doc while debugging a non-related issue and found the staging credentials exposed. The search autocomplete even suggested the credentials, making them visible to the world. Once the issue was discovered, the company cut the contractor's access and rotated all exposed credentials. They also established a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools.
Another incident involved a mid-size retailer whose QR codes were directing users to a competitor's website. The retailer found that the culprit was a disgruntled ex-employee who had not been properly offboarded. The ex-employee used their access to redirect all of the retailer's URLs, resulting in lost customers. Both cases demonstrate that proper access control, offboarding procedures, and basic hygiene can prevent such security incidents.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 2 other outlets
- Passwords stored in public Google Doc then showed up in search results theregister.com
- You may now qualify for Google’s new Search profile, here’s how to check androidauthority.com