Pageloot, a provider of QR‑code solutions for businesses, discovered that an outside contractor had saved staging‑environment credentials in a Google Doc that was set to “Anyone with the link”. The contractor needed the information on multiple devices, but the sharing setting allowed anyone who obtained the link to view the file.
How the leak was found
A Pageloot developer typed the company’s domain into Google Search while working on an unrelated issue. Autocomplete suggested a staging hostname followed by a string that appeared to be a password. The developer followed the link and found a Google Docs URL that could be accessed without signing in.
Google later confirmed that the document had been indexed and appeared in search suggestions. The company quickly removed the contractor’s access and rotated the exposed credentials.
Company response and new policy
Pageloot announced a new rule prohibiting the storage of passwords or other sensitive data in Google Docs, Slack, Notion or similar collaboration platforms. Employees are instructed to use reputable password‑manager tools for any credential storage.
What users can do to protect themselves
Google Docs defaults to a “Restricted” sharing setting, meaning only invited users can open a file. If a document is set to “Anyone with the link” or “Public,” it can be indexed by search engines and accessed by anyone who obtains the link. Users should review the sharing settings on all documents that contain sensitive information, remove unnecessary collaborators, and switch the access level to “Restricted”.
For personal and business use, moving passwords to a dedicated password manager, enabling two‑factor authentication, and keeping security software up to date are recommended steps to reduce the risk of similar exposures.
Original reporting: Fox News (HLL/CB) — read the source article.