A password sat in a Google Doc until Google's autocomplete started offering it around
Here's how the QR code service Pageloot found out it had a problem. A developer was debugging something, typed the company's own domain into Google, and watched the autocomplete drop-down offer up one of their staging server addresses followed by what looked distinctly like a password. It was. A contractor had parked the login details in a Google Doc set to "anyone with the link can view," because that was the easy way to reach them from more than one device. Google indexed the document. Then it started suggesting it.
The company moved quickly once it knew - cut the contractor's access, rotated every affected credential, and banned storing passwords in Google Docs, Slack, Notion or anything similar. As Malwarebytes pointed out writing the incident up on August 18, none of those rules existed before autocomplete happened to surface the thing. Had nobody gone looking, it would still be sitting there.
This is not a company-only habit. Plenty of households keep a shared document with the Wi-Fi password in it, a scan of a passport for a booking, insurance paperwork, the login for the streaming account everyone uses. "Anyone with the link" feels private because there's no obvious front door. It isn't a lock, though - it's an unlisted address, and links get forwarded, pasted into group chats and occasionally crawled. A scan by the firm Metomic across roughly 6.5 million Google Drive files found 40.2% held sensitive information and 0.5% were fully public. Half a percent of six and a half million is still thousands of documents.
Ten minutes in Google Drive, sorted by Shared, checking what each item's sharing setting actually says, is time well spent. Anything containing a password belongs in a password manager instead.
And if those documents live in a cloud folder because it's the only copy you have, Tendvane's one-click backup will put your Documents, Pictures and Desktop onto a drive you physically control.