Security1 publisher3 min readPublished
A staging password went into a Google Doc, and Google's autocomplete found it first
Pageloot's leak was caught by a search box, not a control. "Anyone with the link" behaves like public, and most secrets programs never look inside the documents where credentials actually get parked.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Speaking with The Register, Pageloot founder Siim Kostabi said a contractor working for the company accidentally exposed login details for its staging environment, credentials never meant to leave an internal testing setup.
- The developer stored the staging login details in a Google Doc and set it to "anyone with the link can view"; the credentials file ended up in Google Search.
- Google Search can index Google Docs set to "anyone with the link" if the link becomes discoverable on the public web; such files are not automatically indexed, and it is not known exactly how Google discovered this particular document.
- A Pageloot developer typed the company's domain into Google while debugging, and Google's autocomplete surfaced a staging hostname followed by what looked like a credential string; the document was accessible online.
- Pageloot cut the contractor's access, changed every affected credential, and banned password storage in Google Docs, Slack, Notion and any other shared workspace.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Siim Kostabi, founder of the QR code service Pageloot, told The Register that a contractor exposed the company's staging environment credentials by storing them in a Google Doc and setting it to "anyone with the link can view," after which the file turned up in Google Search [1][2]. The way Pageloot found out is the part worth sitting with: a developer typed the company's domain into Google while debugging, and autocomplete offered a staging hostname followed by what looked like a credential string [4].
Google Docs shared that way are not automatically indexed, and Malwarebytes notes it is not known how Google discovered this particular file, only that the link became discoverable on the public web [3]. Operationally, the distinction between "not indexed by default" and "will not be indexed" is thin. A link-shared doc is an unauthenticated HTTP endpoint holding your secret, and the only thing standing between it and a crawler is that nobody has yet pasted the URL somewhere a crawler reads. Treat the checkbox as a publication decision, because that is how it behaves.
The second lesson is about coverage. Pageloot's response was quick: it revoked the contractor's access, rotated every affected credential, and banned password storage in Google Docs, Slack, Notion and other shared workspaces [5]. But none of those controls existed before autocomplete surfaced the password, and if nobody had noticed, the credentials could have stayed exposed [6]. Nothing in the account was watching the document. Most secrets scanning is aimed at code: commits, history, build logs. Those are the places engineers put credentials on purpose and under review. Collaboration docs are where credentials get parked casually, by contractors, in a hurry, to keep them handy. A program that covers the deliberate path and skips the casual one is monitoring the wrong half.
The scale of the casual path is not speculative. Malwarebytes cites a Metomic scan of roughly 6.5 million Google Drive files in which 40.2 percent contained sensitive information, just over a third were shared externally, and 0.5 percent were fully public [10]. That is on the order of 2.6 million sensitive files and about 32,500 fully public ones [11][12]. Ateam, a Japanese Android game developer, left a Drive instance open to anyone on the internet with the link from March 2017 to November 2023, exposing 1,369 files and personal data for 935,779 people, with the company reporting no evidence of theft after roughly seven years of access [7]. Scale AI left 85 Google Docs containing training material for Meta, Google and xAI editable by anyone with a link, a setup contractors described as "incredibly janky," and later disabled public sharing of managed documents [9]. Public Trello boards did the same job in 2018, when government users exposed passwords and security plans [13]. Verizon's 2025 Data Breach Investigations Report attributes around 60 percent of breaches to human factors including misconfiguration and misuse of valid credentials [14].
Pageloot's other incident makes the same point from the access side: a former employee whose access was never revoked redirected a customer's QR codes to a competitor's site [15].
Worth watching: whether workspace vendors move link sharing to restricted by default, as Scale did after the fact [9], and whether secrets detection extends past repositories into documents and chat. Until it does, the advice stays unglamorous: passwords live in a password manager, not a shared doc, and you check the share dialog before you click it [16].