Tuesday, August 25, 2026
Privacy-First Edition
Back to NNN
Technology

Google Docs password leak reveals a costly security mistake

Video Google battles AI-powered phishing scams targeting Americans Google General Counsel Halimah Delaine Prado joins 'Fox & Friends' to detail how Google is fighting AI-powered phishing scams.

Passwords have a way of ending up in places they were never meant to live. Sometimes convenience wins in the moment, and security becomes tomorrow's problem. One company learned that lesson after a contractor stored credentials in a Google Doc so they could access them from different devices.

Then something happened that should make anyone who uses Google Docs take a closer look at their sharing settings. A developer searching the company's domain on Google saw one of its staging hostnames appear in autocomplete alongside what looked like a credential string. The company investigated and found a Google Docs URL that anyone with the link could access.

That's a rough way to discover that a password has traveled much farther than you intended. Here's how the exposure happened, what Google says about Docs privacy and the simple steps you can take to keep your own passwords and shared files safer.

New! Free live CyberGuy class: Protect Your Money from Today’s Biggest Threats

Reserve your free spot today at CyberGuyLive.com.

WORLD PASSWORD DAY: CHECK IF YOUR PASSWORDS ARE SAFE

A computer screen displaying text related to a Google Docs password leak security incident. (Kurt "CyberGuy" Knutsson)

The story was reported by The Register and comes from Siim Kostabi, co-founder of Pageloot, a company that provides QR codes for businesses. Kostabi said his company brought in an outside contractor to help with back-end API integrations. The contractor had credentials for the company's staging environment, which is essentially a test version of its system.

The contractor wanted easy access to those credentials from multiple devices. So they put the information into a Google Doc and set the document so anyone with the link could view it. Later, a Pageloot developer was working on an unrelated problem and typed the company's domain into Google Search. Autocomplete surfaced one of the staging hostnames followed by what appeared to be a credential string.

The team checked and found the accessible Google Docs URL. The Register reported that Google Search had indexed the document and offered information from it as a search suggestion. Pageloot quickly cut off the contractor's access and rotated the exposed credentials. The company also adopted a rule against storing passwords in Google Docs, Slack or Notion and other collaboration tools.

Before you start worrying that every Google Doc you have ever created could suddenly appear in a search, there is an important piece of context. Google told CyberGuy that Google Docs are restricted by default. The person who creates the document controls how it gets shared.

Google's current Drive guidance says Restricted means only people with access can open a file. If you select Anyone with the link , anyone who gets that link can use the file without signing in to a Google Account. Google separately lists a Public setting, when available, that allows anyone to find the file through Google Search.

Google also told CyberGuy that a link to a publicly shared Doc may be indexed if someone posts that link somewhere public where a search engine crawler can find it. The Register says the Pageloot document eventually surfaced through Google Search autocomplete. However, the report does not explain how Google first discovered the Docs URL. For the rest of us, the useful lesson is simple: pay attention to the sharing setting before putting anything sensitive in a cloud document.

Kostabi also described a separate incident involving one of Pageloot's customers. The mid-size retailer discovered that its QR codes had started sending shoppers to a competitor's website.

According to Kostabi, the company investigated and found that a former employee's credentials had never been revoked. He said the former employee used that lingering access to redirect the retailer's URLs. That mistake carries a very familiar lesson.

When someone no longer needs access to an account or shared file, their access should go away too. That applies at work, but it can also apply at home. Maybe you once shared a financial document with an accountant. Perhaps an old household file still includes someone who no longer needs it. Shared access can be easy to forget because the file quietly remains in Google Drive.

WHAT YOUR INTERNET PROVIDER, WEBSITES AND ADVERTISERS SEE

A company discovered staging credentials stored in a Google Doc had surfaced through Google Search autocomplete after the file was shared too broadly. (Kurt "CyberGuy" Knutsson)

You do not have to run a business to learn something from this story. Plenty of people use Google Docs and Drive to keep household information, travel plans or tax documents and other details they want available across devices.

The danger comes when sensitive information lands in a file with broader access than you realize. A Google Doc can feel private because you remember sending the link to only one person. What really counts is who currently has permission to open it and what the General access setting says. That makes this a good time to check the files you would least want a stranger opening.

A few small changes can reduce the chance that an old shared file or exposed password turns into a much bigger security problem.

If you have passwords sitting in a Google Doc right now, move them to a reputable password manager. Password managers are designed to securely store logins and make them available across your devices. They can also help you create unique passwords instead of reusing the same one. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com for options and what to look for. After moving a password, delete it from the document. If other people may have had access to the file, change that password too.

Start with documents containing financial information or account details.

Google says switching General access to Restricted means only people with access can open the file.

This setting can be handy when you need to share something quickly. However, anyone who gets the link can access the file without signing in to a Google Account. That link can also get forwarded or copied somewhere you never expected. For sensitive documents, share the file directly with specific people instead.

Open the sharing settings on important files and scan the list of people who can still get in. If someone no longer needs access, remove them. This is especially worth doing after you finish working with a contractor or service provider. At home, the same idea applies when you have shared a document temporarily and the reason for sharing it has passed.

Changing a Google Doc from broad access to Restricted helps close the door, but it cannot undo exposure that may have already happened. If a password was sitting in a document other people could access, change it. Then check the account's recent login or security activity for anything you do not recognize.

Two-factor authentication adds another step when someone tries to sign in to your account. That can help protect you if a password gets stolen. CyberGuy's guide to multi-factor authentication apps can help you strengthen accounts that support this added protection.

Strong antivirus software adds another layer of protection on your computer and phone. It cannot fix a Google Doc with the wrong sharing setting. However, it can help detect malicious downloads, phishing attempts and other threats that may follow if criminals get hold of your login information. Keep your security software updated and make sure real-time protection stays turned on. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

Identity theft protection makes the most sense when an exposed document contained more than a password. For example, you may want extra monitoring if someone gained access to your Social Security number, financial account information or other highly sensitive personal data. Identity theft protection services can watch for signs that your information is being misused. Some also alert you to suspicious activity tied to your identity. If the exposure involved only one account password, changing that password and securing the account may be enough. The level of protection you need depends on what information was actually exposed. See my tips and best picks on Best Identity Theft Protection at CyberGuy.com.

You probably have old Google Drive files you have not opened in months or even years. Spend a few minutes checking the sharing settings on documents containing sensitive information. You may find an old permission you completely forgot about. For more ways to lock down cloud files, see our guide on protecting sensitive documents and controlling file access.

Google also addressed a separate privacy question with CyberGuy. The company told us that it does not use private Workspace content, including Drive and Docs, to train its foundational AI models such as Gemini. Google's published Workspace guidance likewise says Workspace data isn’t used to train or improve the underlying generative AI models that power Gemini, Search and other systems outside Workspace without permission. That issue is separate from what happened in the Pageloot story. This case centered on how the document was shared and how credentials were handled.

FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK

Google Docs are Restricted by default, but changing sharing permissions can expose sensitive information to anyone who gets the link. (Kurt "CyberGuy" Knutsson)

What gets me about this story is how ordinary the original decision probably felt. Someone needed a password on more than one device and chose an easy place to put it. That shortcut eventually left company credentials where Google Search autocomplete could surface them. The second incident carries another lesson I think all of us can use. Access should have an expiration date. When somebody no longer needs to open one of your files or accounts, remove them. I would also take five minutes today and look at the Google Docs you care about most. Check the people who can open them and look at the General access setting. You may find nothing wrong. Great. But if you uncover an old shared link or a person who should no longer have access, you will be glad you looked before somebody else did.

When was the last time you checked who can still open the Google Docs and Drive files you've shared over the years? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Kurt "CyberGuy" Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on "FOX & Friends." Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.

Read original at Fox News

The Perspectives

0 verified voices · Three viewpoints · Real discourse

Left
0
Be the first to share a left perspective
Center
0
Be the first to share a center perspective
Right
0
Be the first to share a right perspective

Related Stories