A developer working for Pageloot, a company specializing in QR code services, publicly exposed credentials for a staging environment by storing them in a Google Doc accessible to anyone with the link. The exposure was discovered when an internal Pageloot developer, while debugging an unrelated issue, typed the company's domain into Google Search. Google's autocomplete feature then suggested a search query that included one of Pageloot's staging hostnames followed by what appeared to be a credential string. This led to the discovery of the publicly indexed Google Docs URL containing the sensitive information.
Siim Kostabi, co-founder of Pageloot, confirmed that the incident involved an external contractor hired to assist with API integrations. The contractor sought a method to access credentials across multiple devices used for the project and opted to store them in a Google Doc, which was inadvertently configured for public access.
Upon discovering the exposed credentials, Pageloot immediately revoked the contractor's access and rotated all compromised credentials. The company also implemented a new policy prohibiting the storage of passwords in collaboration tools such as Google Docs, Slack, and Notion.
Kostabi emphasized that while the exposed credentials were for a staging server, such information still holds significant value if misused. He highlighted the importance of robust access control and proper security hygiene to prevent such incidents.
In a separate but related incident, Kostabi recounted a situation involving a Pageloot customer, a mid-sized retailer. This customer experienced their QR codes redirecting users to a competitor's website. Investigation revealed that a disgruntled former employee's credentials had not been revoked post-departure. The ex-employee subsequently used this unrevoked access to maliciously redirect the retailer's URLs, resulting in customer loss.
Kostabi noted that both the Google Docs exposure and the ex-employee incident underscore the necessity of stringent access management, including thorough offboarding procedures and regular access reviews. He stressed that treating shared documents as private vaults is a critical security oversight.






