Google Search Indexes Credentials from Public Google Doc
TL;DR. A developer stored staging server credentials in a public Google Doc, which Google Search indexed and offered as an autocomplete suggestion, exposing sensitive information. - The security lapse occurred when a contractor used a public Google Doc to manage staging environment passwords. - An employee discovered the exposed credentials when typing their domain into Google Search, which suggested the hostname and credential string. - The company immediately revoked contractor access and rotated all compromised credentials following the discovery.
- Public Google Doc used to store staging credentials.
- Google Search indexed the document, making credentials searchable.
- Company discovered the breach via Google Search autocomplete.
- Access revoked and credentials rotated immediately.
Sources
- Passwords stored in public Google Doc then showed up in search results — theregister.com