{
  "id": 743100,
  "title": "Passwords stored in public Google Doc then showed up in search results",
  "url": "https://urgent.news/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-13T07:00:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028"
  },
  "original_language": "en",
  "account": "Welcome to PWNED, the weekly column that highlights security failures and offers lessons from them. Our story today is about the misfortune of storing passwords in a public Google Doc, which then appeared in search results.\n\nPageloot, a company that provides QR codes for marketing, hired a contractor to assist with API integrations. This developer had access to the staging environment's credentials and wanted to view them on multiple devices. Instead of using a secure password manager, the developer stored the credentials in a publicly accessible Google Doc, which anyone could find by simply searching for the company's domain.\n\nA company employee discovered the Google Doc while debugging a non-related issue and found the staging credentials exposed. The search autocomplete even suggested the credentials, making them visible to the world. Once the issue was discovered, the company cut the contractor's access and rotated all exposed credentials. They also established a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools.\n\nAnother incident involved a mid-size retailer whose QR codes were directing users to a competitor's website. The retailer found that the culprit was a disgruntled ex-employee who had not been properly offboarded. The ex-employee used their access to redirect all of the retailer's URLs, resulting in lost customers. Both cases demonstrate that proper access control, offboarding procedures, and basic hygiene can prevent such security incidents.",
  "summary": "Developer spotted hostname and credential string lurking in autocomplete",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Passwords stored in public Google Doc then showed up in search results",
        "url": "https://urgent.news/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results-744605",
        "published": "2026-08-13T07:00:00.000Z"
      },
      {
        "outlet": "Android Authority",
        "title": "You may now qualify for Google’s new Search profile, here’s how to check",
        "url": "https://urgent.news/2026/08/13/you-may-now-qualify-for-googles-new-search-profile-heres-how-to-check",
        "published": "2026-08-13T10:10:52.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}