Google Doc Password Leak Exposes Staging Credentials Through Autocomplete
A company discovered that its staging credentials were exposed through Google Search autocomplete after being stored in a Google Doc by an outside contractor. The contractor had put the information into a document to access it from multiple devices, but set the document to allow anyone with the link to view it.
The team at Pageloot quickly cut off the contractor's access and rotated the exposed credentials, but adopted a rule against storing passwords in Google Docs or other collaboration tools.
Google explained that Google Docs are restricted by default, with the person who creates the document controlling how it gets shared. However, if someone posts a link to a publicly shared Doc somewhere public, it can be indexed and appear in search results.
The incident highlights the importance of paying attention to sharing settings when storing sensitive information in cloud documents.