Google Doc Exposes Staging Credentials After Indexing by Search Engine
A developer at Pageloot, a company that provides QR codes for businesses, made a critical mistake by storing staging environment credentials in a publicly accessible Google Doc. The doc was indexed by Google Search and became available to anyone who typed the correct search terms.
Siim Kostabi, co-founder of Pageloot, recalled how an employee discovered the issue when searching their company's domain on Google. The autocomplete suggested a staging hostname followed by what appeared to be a credential string.
Kostabi's team immediately cut access for the contractor and rotated all exposed credentials after discovering the problem. They also implemented a new rule prohibiting password storage on collaboration tools like Google Docs, Slack, or Notion.