Security1 distinct publisher3 min readUpdated
Pageloot's leak was caught by a search box, not a control. "Anyone with the link" behaves like public, and most secrets programs never look inside the documents where credentials actually get parked.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Pageloot's leak was caught by a search box, not a control. "Anyone with the link" behaves like public, and most secrets programs never look inside the documents where credentials actually get parked.
Siim Kostabi, founder of the QR code service Pageloot, told The Register that a contractor exposed the company's staging environment credentials by storing them in a Google Doc and setting it to "anyone with the link can view," after which the file turned up in Google Search [1][2]. The way Pageloot found out is the part worth sitting with: a developer typed the company's domain into Google while debugging, and autocomplete offered a staging hostname followed by what looked like a credential string [4].
Google Docs shared that way are not automatically indexed, and Malwarebytes notes it is not known how Google discovered this particular file, only that the link became discoverable on the public web [3]. Operationally, the distinction between "not indexed by default" and "will not be indexed" is thin. A link-shared doc is an unauthenticated HTTP endpoint holding your secret, and the only thing standing between it and a crawler is that nobody has yet pasted the URL somewhere a crawler reads. Treat the checkbox as a publication decision, because that is how it behaves.
The second lesson is about coverage. Pageloot's response was quick: it revoked the contractor's access, rotated every affected credential, and banned password storage in Google Docs, Slack, Notion and other shared workspaces [5]. But none of those controls existed before autocomplete surfaced the password, and if nobody had noticed, the credentials could have stayed exposed [6]. Nothing in the account was watching the document. Most secrets scanning is aimed at code: commits, history, build logs. Those are the places engineers put credentials on purpose and under review. Collaboration docs are where credentials get parked casually, by contractors, in a hurry, to keep them handy. A program that covers the deliberate path and skips the casual one is monitoring the wrong half.
The scale of the casual path is not speculative. Malwarebytes cites a Metomic scan of roughly 6.5 million Google Drive files in which 40.2 percent contained sensitive information, just over a third were shared externally, and 0.5 percent were fully public [10]. That is on the order of 2.6 million sensitive files and about 32,500 fully public ones [11][12]. Ateam, a Japanese Android game developer, left a Drive instance open to anyone on the internet with the link from March 2017 to November 2023, exposing 1,369 files and personal data for 935,779 people, with the company reporting no evidence of theft after roughly seven years of access [7]. Scale AI left 85 Google Docs containing training material for Meta, Google and xAI editable by anyone with a link, a setup contractors described as "incredibly janky," and later disabled public sharing of managed documents [9]. Public Trello boards did the same job in 2018, when government users exposed passwords and security plans [13]. Verizon's 2025 Data Breach Investigations Report attributes around 60 percent of breaches to human factors including misconfiguration and misuse of valid credentials [14].
Pageloot's other incident makes the same point from the access side: a former employee whose access was never revoked redirected a customer's QR codes to a competitor's site [15].
Worth watching: whether workspace vendors move link sharing to restricted by default, as Scale did after the fact [9], and whether secrets detection extends past repositories into documents and chat. Until it does, the advice stays unglamorous: passwords live in a password manager, not a shared doc, and you check the share dialog before you click it [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Speaking with The Register, Pageloot founder Siim Kostabi said a contractor working for the company accidentally exposed login details for its staging environment, credentials never meant to leave an internal testing setup.
The developer stored the staging login details in a Google Doc and set it to "anyone with the link can view"; the credentials file ended up in Google Search.
Google Search can index Google Docs set to "anyone with the link" if the link becomes discoverable on the public web; such files are not automatically indexed, and it is not known exactly how Google discovered this particular document.
A Pageloot developer typed the company's domain into Google while debugging, and Google's autocomplete surfaced a staging hostname followed by what looked like a credential string; the document was accessible online.
Pageloot cut the contractor's access, changed every affected credential, and banned password storage in Google Docs, Slack, Notion and any other shared workspace.
None of those fixes existed before autocomplete surfaced the password; if nobody had spotted it, the credentials could have remained exposed.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source account, corroborated only by secondhand precedents
The core incident rests entirely on one publisher relaying the founder's own telling: no timeline, no exposure duration, no artifacts, no Google comment, and the article itself concedes it does not know how the document became discoverable. Strength comes from the named third-party datapoints around it (Ateam, Scale AI, Metomic, DBIR 2025), which are themselves cited rather than verified here, plus one arithmetic extrapolation from the Metomic percentages.
Failure pattern documented across several organizations and one large scan
This measures how widely the underlying behavior is observed, not uptake of a product. Concrete instances span a small QR vendor, a Japanese game developer with 935,779 people affected, a major AI data-labeling firm, and 2018 Trello exposures by government users; a scan of ~6.5M Drive files puts 0.5% fully public and 40.2% sensitive, and DBIR 2025 attributes ~60% of breaches to human factors. Countervailing: the Pageloot case itself is a single small company with no measured blast radius, and two of the datapoints are undated in the source.
Mildly overstated: framing outruns the single anecdote
The cluster's dek asserts that "most secrets programs never look inside the documents where credentials actually get parked" - a claim no supplied source measures. The Metomic and DBIR figures speak to sensitive-data sprawl and human-factor breach causation, not to secrets-program coverage. The core incident is one small vendor's self-reported near-miss with no evidence anyone else found or used the credentials, yet it is presented as emblematic. Offsetting the gap: the mechanism claim is stated carefully with its unknowns acknowledged, and the prescriptive advice is modest.
Vendor-published advisory citing vendor research, with a self-exculpating source
The only publisher is a consumer security vendor, and the article's prescription - use a password manager, watch what you Share - aligns with the security-product category it sells. Its prevalence anchor comes from Metomic, a security company with a commercial interest in demonstrating Drive data sprawl, and the DBIR is a vendor report. On the subject side, Pageloot's founder is narrating an incident caused by a contractor and a former employee, a framing that shifts fault outward while showcasing rapid remediation. None of these incentives is disclosed in the text.
Moderate-low: internally consistent but unverified and single-sourced
One publisher, one item, and the load-bearing incident is founder testimony with no dates or impact assessment, so the cluster cannot be cross-checked. Confidence is held up by the article's own hedging on the indexing mechanism and by specific, attributable third-party figures; it is held down by the absence of corroboration, of any Google or Scale AI response captured here, and by the undated Metomic, Scale and DBIR datapoints.
science
21 language models, one habit: tell them your politics and they adopt them1 distinct publisher
product
The dirtiest part of the AI gas buildout is a turbine spec, not a nameplate1 distinct publisher
invest
The labs got better at watching their agents escape. They did not get better at stopping them.1 distinct publisher
build
First-turn evals test the safest part of your product, a 90,000-exchange audit finds1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026