Passwords often find themselves in unexpected places, often due to a moment of convenience. Such was the case for one company that learned this lesson the hard way when a contractor stored sensitive credentials in a Google Doc to have access across different devices.
Things took a turn when a developer, searching the company’s domain, noticed a staging hostname appear alongside what seemed like a credential string in Google’s autocomplete suggestions. Upon investigation, the team found a Google Docs link that anyone with the URL could access.
This incident serves as a wake-up call for Google Docs users regarding the importance of sharing settings. Here’s an overview of how the exposure occurred, Google’s stance on Docs privacy, and some basic steps to enhance the security of your passwords and shared files.
How Credentials Ended Up in a Google Doc
The story was outlined by Siim Kostabi, co-founder of Pageloot, a QR code provider. He recounted that they engaged a contractor for back-end API integrations, who needed easy access to credentials for the company’s test environment. To do this, the contractor placed the information in a Google Doc and configured it so that anyone with the link could view it.
Later, while addressing an unrelated issue, a Pageloot developer accidentally stumbled upon this Google Doc through a Google Search suggestion. It turned out that Google had indexed the document, leading to the accessibility issue. After this revelation, Pageloot immediately revoked the contractor’s access and changed the exposed credentials. The company now prohibits the storage of passwords in Google Docs and similar collaboration tools.
Google’s Privacy Settings Explained
Before you panic and think all your documents are at risk, it’s important to note that Google Docs have restricted sharing settings by default. According to Google, the document creator manages how it gets shared.
Under Google’s guidelines, “Restricted” means that only explicit users can access a document. The setting “Anyone with the link” allows anyone with that link to access it without needing to log into a Google account. Additionally, public documents may be indexed if someone posts the link somewhere accessible to search engine crawlers. The Pageloot issue highlights the importance of staying vigilant about your document’s sharing settings before adding sensitive information.
A Different Access Problem Caused by a Former Employee
Kostabi also shared a separate issue where one of Pageloot’s clients discovered that their QR codes were directing customers to a competitor. This was traced back to a failure to revoke access for a former employee. The lingering credentials had allowed that ex-employee to redirect the retailer’s URLs. It’s a reminder that when someone no longer needs access—be it at work or at home—their access should be revoked.
Perhaps you’ve shared a financial document with an accountant at one time; if that document still has their access, it could lead to serious issues.
Why This Incident Should Matter to You
This situation is a relevant lesson for everyone, not just businesses. Many people use Google Docs not just for work but also for personal items like travel plans or tax documents, which can contain sensitive information. The problem arises when private data is carelessly placed in a document with broader access than intended. It’s easy to think a document is secure if you only shared it with one person, yet it’s crucial to double-check the current settings and permissions.
Tips for Keeping Passwords and Google Docs Secure
Adopting a few minor changes can significantly reduce the risk of exposed passwords and shared documents.
1) Avoid Using Google Docs for Passwords
If you currently have passwords in a Google Doc, it’s wise to transfer them to a reliable password manager, designed for securely storing and managing logins across devices. Don’t forget to delete any remaining instances from the document, and if others had access to it, change the password itself.
2) Review Access for Your Important Documents
Start with files that hold financial or sensitive information.
- Open Google Drive.
- Locate the relevant file.
- Click on Share.
- Review the people who have access.
- Remove anyone who doesn’t need it.
- Check the General access setting.
- Select Restricted if you want to limit it to approved individuals.
Switching the General access to Restricted ensures only authorized individuals can access your document.
3) Share with Caution
Be mindful of using the “Anyone with the link” setting. It may seem convenient but can lead to unintended access if the link is shared further than anticipated. For sensitive files, share them directly with specific people.
4) Remove Unnecessary Access
It’s good practice to regularly review the sharing settings of important documents. If you spot someone who no longer needs access, remove them. This is especially relevant after working with contractors or when sharing files temporarily.
5) Change Exposed Passwords Immediately
While tightening access settings is essential, it doesn’t negate any breach that may have already occurred. If passwords were accessible to others, change them quickly and monitor the account for suspicious activity.
6) Enable Two-Factor Authentication
Implementing two-factor authentication provides an additional layer of security for your accounts, which can be crucial if passwords are compromised.
7) Use Antivirus Software
Having strong antivirus software is another protective measure, though it can’t solve issues caused by misconfigured sharing settings. Nonetheless, it helps identify malware and phishing attempts that may accompany leaked credentials.
8) Consider Identity Theft Protection for Exposed Data
If sensitive personal data, such as your Social Security number, was potentially exposed, identity theft protection offers monitoring services for suspicious activity. If only a single password was compromised, changing it may suffice.
9) Don’t Forget to Check Shared Files Regularly
Chances are you have older Google Drive files that haven’t been reviewed in a long time. Take a moment to examine the sharing settings on any sensitive documents—you might find outdated permissions.
Google’s Statement on Privacy with Workspace
In another note, Google clarified that it does not use private Workspace content, like Drive or Docs, for training its AI models, ensuring users’ privacy regarding this issue. This information is separate from the case concerning Pageloot, which was primarily about document sharing issues.
Key Takeaways
This story serves as a stark reminder about the seemingly minor decisions we make regarding file sharing. The initial choice to store credentials for convenience led to significant exposure risk. Additionally, it emphasizes the importance of removing access when it’s no longer needed. Today, take a few minutes to check the permissions on your most important Google Docs. You might discover nothing amiss, which is great. But if you find an old link or someone who shouldn’t have access anymore, you’ll be glad you checked before a potential breach happens.
When was the last time you reviewed who can access your shared Google Docs? Let us know your thoughts.






