Passwords stored in public Google Doc then showed up in search results

DemiGuru1 pts0 comments

Passwords stored in public Google Doc then showed up in search results

Jump to main content

Search

REG AD

SECURITY

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

Avram Piltch

Avram<br>Piltch

US EDITOR

US editor

Published<br>thu 13 Aug 2026 // 08:00 UTC

PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.”<br>Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.<br>Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands.

REG AD

He explains that his company brought in a contractor to help with some API integrations on the back end. That developer had the credentials for the staging environment and wanted to be able to view them across different devices they were using for the job.

REG AD

So what was the developer’s solution to the very common problem of keeping track of usernames and passwords? They could have chosen a password manager. They could have written the passwords down in a paper notebook and kept it hidden from prying eyes. They could have gotten a password tattoo. They could even have emailed the passwords to themselves and it would have been smarter than what they did.<br>Instead, the outside developer decided to store their password in a Google Doc. And they set that Google Doc to be viewable by anyone on the internet who had the link. And then, one day, an employee at the company found the Google Doc with the staging credentials in it because Google Search had indexed it and offered it as a search suggestion.<br>“A developer on our team was debugging something unrelated and typed our domain into Google Search,” Kostabi recalls. “The autocomplete surfaced one of our staging hostnames followed by what looked like a credential string. We checked, and there was a publicly accessible Docs URL.”<br>Yikes! Just imagine that not only are your company’s credentials available to anyone online, but they are indexed in Google Search for the world to find!<br>Once they discovered the problem, Kostabi’s company immediately cut access for that contractor and rotated all of its exposed credentials. They also set a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools.

MORE CONTEXT

IT department put sticky notes on the laptops to help employees log in

Headteacher had the most guessable username-password combo you could imagine

Talking smack about a doctor got him access to private medical files

Law firm insisted on one password to rule them all

In a separate incident, Kostabi heard from a Pageloot customer, a mid-size retailer, whose QR codes were suddenly directing users to a competitor’s site. After investigating, he found that a disgruntled ex-employee’s credentials had not been revoked and that the former employee had used that access to redirect all of the retailer’s URLs, costing it customers.<br>The takeaway from both of these problems is that you need to carefully control access. Former employees should immediately lose access to everything and current contractors should be reasonably intelligent people you can trust.<br>“Both situations were completely avoidable with basic hygiene,” Kostabi said. “Proper offboarding, access reviews, and not treating shared docs like private vaults.” ®

pwned<br>security

REG AD

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

PERSONAL TECH

Epic Games dismisses Apple's simplified EU App Store fees as 'junk'

Consumer group sees improvements on paper but warns the devil remains in the detail

devops

Platform Engineering 2.0: your platform was built for a different era. AI just exposed it

PARTNER CONTENT: Platform engineering won the argument. Now it has to grow up fast and evolve for the AI era.

Security

Flock surveillance backlash mounts as fiendish Halloween plans circulate

CEO apologizes for police misuse as activists call for vandal action against license plate cameras

COLUMNISTS

Be a hater all you want, AI's here to stay

The good news? One of the worst bits, tech giants controlling it all, might soon be over

AI AND ML

More than half of Americans now view AI negatively

Concern continues to climb for adults under 30, as people fear being replaced by AI

MOST POPULAR

AI and ml

Google buys crashed airline Spirit’s data at auction, because AI

AI and Ml

Excel's Copilot function is headed for the Recycle Bin

DEVOPS

GitHub has Issues as repo...

google search passwords kostabi credentials access

Related Articles