logo

Passwords stored in public Google Doc then showed up in search results

ID: 1db6b1d6-9c5a-5160-b3e9-7342dbac9f78

STIX ID: report--1db6b1d6-9c5a-5160-b3e9-7342dbac9f78

Feed Name: The Register (Security)

Threat Score
45/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

The article recounts two access-control failures: a developer saved staging credentials in a publicly shared Google Doc that became indexed by Google Search, exposing secrets, and an unrevoked ex-employee abused credentials to redirect a retailer’s QR codes—both incidents underscore poor credential hygiene, insufficient offboarding, and the need to prohibit storing secrets in collaborative documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.