Google Docs password leak exposes costly security mistake
A contractor’s habit of storing company passwords in a Google Doc led to a costly security exposure at Pageloot, a QR code business. According to Fox News, co-founder Siim Kostabi said a developer discovered a staging hostname and credential string appearing in Google Search autocomplete after the document was set to “anyone with the link” access.
The Register first reported the incident. Pageloot cut off the contractor’s access and rotated the exposed credentials. Google said Docs are restricted by default, but sharing settings determine broader exposure. The company also banned storing passwords in Google Docs, Slack or Notion.
Rifnote
Loading your desk