New York Tuesday, August 25, 2026

Boldest Voice

Search

Technology

Google Docs password leak exposes costly sharing mistake

A contractor's decision to store staging credentials in a Google Doc with link-based access led to the document being indexed by Google Search, exposing the company's passwords. The incident highlights the risks of cloud file sharing and the importance of auditing access permissions.

Google Docs password leak reveals a costly security mistake

A contractor's decision to store company credentials in a Google Doc has turned into a cautionary tale about cloud file sharing. The incident, reported by The Register, began when an outside contractor working with Pageloot, a QR code provider, saved staging environment passwords into a Google Doc. The contractor set the document so that anyone with the link could view it, intending to access the credentials from multiple devices. That choice eventually exposed the company's sensitive information through Google Search.

Siim Kostabi, co-founder of Pageloot, said a developer later typed the company's domain into Google Search while working on an unrelated issue. Autocomplete surfaced one of the company's staging hostnames alongside what appeared to be a credential string. The team investigated and found the Google Docs URL was publicly accessible. Google Search had indexed the document and was offering information from it as a search suggestion. Pageloot responded by revoking the contractor's access and rotating the exposed credentials. The company also adopted a policy against storing passwords in Google Docs, Slack, Notion, or other collaboration tools.

Google told CyberGuy that Google Docs are restricted by default, meaning the creator controls how a file is shared. The company's Drive guidance states that selecting "Anyone with the link" allows anyone who receives the link to open the file without signing in to a Google Account. A separate "Public" setting, when available, allows anyone to find the file through Google Search. Google also noted that a link to a publicly shared document may be indexed if someone posts that link in a public location where a search engine crawler can find it. The Register's report does not explain how Google first discovered the Pageloot document's URL.

Kostabi also described a separate incident involving one of Pageloot's customers. A midsize retailer discovered that its QR codes had begun redirecting shoppers to a competitor's website. The investigation found that a former employee's credentials had never been revoked, and the former employee used that lingering access to redirect the retailer's URLs. The lesson, Kostabi said, is that access should be removed when someone no longer needs it, whether at work or at home.

The risks extend beyond businesses. Many people use Google Docs and Drive to store household information, travel plans, tax documents, and other details they want available across devices. The danger arises when sensitive information lands in a file with broader access than the owner realizes. A Google Doc can feel private because the owner remembers sending the link to only one person, but what matters is who currently has permission to open it and what the general access setting says.

Security experts recommend checking the files you would least want a stranger to open. If passwords are currently stored in a Google Doc, moving them to a reputable password manager is a safer option. Password managers are designed to securely store logins and make them available across devices, and they can help generate unique passwords instead of reusing the same one. Reviewing sharing settings and revoking access for former collaborators or employees can prevent old shared files from becoming a much larger security problem.

Austin Emerson

Author

Editorial Writer

Austin Emerson covers public affairs, politics, business, culture and daily news for Boldest Voice. The role focuses on verification, context, and clear explanations for readers.

Read on