Contractor’s Google Docs mistake exposes company passwords via search autocomplete
A contractor stored staging-environment credentials in a Google Doc set to “anyone with the link,” which was later indexed by Google and surfaced in search suggestions, prompting the company to revoke access and change the passwords.
Pageloot engaged an external contractor for back-end API work, and the contractor placed staging-environment login details in a Google Doc configured for “anyone with the link” access. When a Pageloot developer typed the company’s domain into Google Search, the autocomplete feature displayed a staging hostname followed by what looked like a password string, revealing that the document had been indexed and was publicly reachable.
The company responded by cutting off the contractor’s permissions, rotating the compromised credentials, and adopting a rule prohibiting the storage of passwords in Google Docs, Slack, Notion, or similar platforms. Google explained that documents are private by default and only become searchable when the owner explicitly chooses a public or link-accessible setting, which can then be crawled by search engines. The incident underscores the need for careful review of sharing settings and the removal of unnecessary access, especially after a contractor’s work is finished. Additional guidance was offered on securing passwords, using password managers, and regularly auditing shared files.
Why it matters
It shows how easy sharing settings can expose sensitive credentials, risking security breaches for businesses and individuals.
In this story
