Google Docs link sharing has once again proven to be a hidden risk, as QR code provider Pageloot recently discovered that sensitive credentials for its staging environment were unintentionally exposed through a misconfigured document. The incident highlights how sharing documents with anyone who has the link can result in unexpected public exposure, especially when search engines become involved.
Google Docs Link Sharing Led to Credential Exposure
Pageloot, a company specialising in QR code services, found itself in the spotlight when a contractor stored staging environment credentials in a Google Doc. Critically, the document’s sharing settings were configured to allow ‘anyone with the link’ to view its contents. This level of access, while convenient for collaboration, bypasses authentication controls for anyone who obtains the URL. The risk lies in the fact that, under certain circumstances, such documents can be indexed by search engines if their links become discoverable on the public web.
The exposure came to light in a particularly revealing way. A Pageloot developer, while debugging, typed the company’s domain into Google Search. The autocomplete feature unexpectedly suggested a combination of a staging environment hostname and what appeared to be a credential string. Investigating further, the team found that Google Search had indexed the contents of the Google Doc, making the sensitive information retrievable by anyone who stumbled upon the right search terms.
Timeline of the Incident
- 13 August 2026: The Register reports Pageloot’s account of the exposure and response.
- 18 August 2026: Malwarebytes publishes a deeper analysis of the event and its implications.
- The actual date of exposure and discovery remains undisclosed, but Pageloot acted swiftly upon finding the breach.
Upon discovery, Pageloot immediately revoked the contractor’s access to sensitive systems and rotated all credentials that had been exposed. The company also instituted a new policy banning the storage of passwords and credentials in collaborative tools such as Google Docs, Slack and Notion. These actions prevented any reported abuse of the leaked credentials, and there is no evidence that the incident affected production systems or customer data.
How Google Docs Became Publicly Searchable
The technical root cause was straightforward: the Google Doc containing the credentials was set to ‘anyone with the link’, making it accessible to anyone who had or discovered the URL. While Google Docs with this setting are not automatically indexed, they can become indexed if the link is posted or referenced on a publicly accessible web page, or if the document is explicitly published to the web.
In Pageloot’s case, the specific way the document link became discoverable to Google’s crawlers remains unknown. Nevertheless, Google Search had indexed enough of the document to display credential fragments in autocomplete results. This incident illustrates a little-known risk: when documents are shared too widely, search engines can sometimes surface their contents well beyond the intended audience.
There is no indication that external threat actors accessed the credentials before they were revoked. However, the risk was real. Anyone who found the indexed document could have used the credentials to access Pageloot’s staging environment.
Similar Exposures Across the Industry
Pageloot’s experience is not unique. Other organisations have faced similar problems due to misconfigured sharing settings in online collaboration tools:
- Ateam: A Japanese game developer left a Google Drive instance set to ‘anyone with the link’ for more than six years, exposing over 1,300 files and personal data of nearly a million individuals.
- Scale AI: This data-labelling company left 85 Google Docs with sensitive training material editable by anyone with the link, prompting a policy change to disable public document sharing.
- Metomic Research: An analysis of 6.5 million Google Drive files found that 40 percent contained sensitive data, with over a third shared externally and 0.5 percent fully public.
These examples underscore that the risk is not limited to Google Docs. Other SaaS tools like Slack, Notion, and Trello have also seen inadvertent leaks due to permissive sharing settings.
Technical Breakdown: Indexing and Discovery
The incident at Pageloot did not involve a software vulnerability or external hack. Instead, it was a classic case of human error and misconfiguration. Documents shared with ‘anyone with the link’ are a common convenience but can lead to exposure if those links leak onto the wider web. Search engines, including Google, can crawl and index these documents if they are referenced on public sites, posted in forums, or otherwise made discoverable.
Google Workspace administrators can configure organisation-wide policies to limit external sharing and monitor for risky sharing behaviours. Google also provides guidance for removing documents from search results and controlling what content is accessible beyond the organisation.
Summary of the Key Events
- Pageloot contractor stored staging credentials in a Google Doc set to ‘anyone with the link’.
- Google Search indexed the document, making credentials visible in autocomplete suggestions.
- Pageloot discovered the exposure, revoked access, rotated credentials and updated internal policies.
- No confirmed evidence of malicious exploitation before remediation.
Why This Matters and What To Do Next
This incident demonstrates that even documents not explicitly published can become searchable if link sharing is too permissive. Small and medium businesses using Google Workspace or any SaaS collaboration tool should be alert to the risks of ‘anyone with the link’ sharing. Policies that restrict external sharing and prohibit storing credentials in documents are essential to prevent accidental leaks.
Originally reported by malwarebytes.com.






