Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

Staging server passwords exposed after contractor saved them in a public Google Doc

A contractor for Pageloot stored staging environment credentials in a Google Doc set to public, and the document appeared in Google Search suggestions.

Pageloot engaged an outside developer to help integrate APIs and provided the individual with staging environment login details. Instead of using a password manager or other secure method, the developer saved the credentials in a Google Document that was configured to be viewable by anyone who possessed the link. The document was later indexed by Google, and an employee noticed the staging hostname and credential string appear as an autocomplete suggestion while searching the company’s domain.

Upon discovery, Pageloot cut off the contractor’s permissions, rotated all compromised credentials, and instituted a policy prohibiting the storage of passwords in Google Docs, Slack, Notion, or similar collaboration platforms. The incident underscores the importance of proper off-boarding and rigorous access-review practices.

Why it matters

It shows how easy it is for insecure password storage to become publicly searchable, risking corporate systems.

In this story

password leakpublic Google Docsearch autocompletestaging credentialsaccess controloffboarding