Be careful what you put in “anyone with the link” Google Docs
August 18, 2026 · Malwarebytes · Severity: MEDIUM
The founder of QR generation service Pageloot learned the hard way that sensitive information stored in Google Docs with anyone with the link permissions can be indexed by Google Search. A contractor accidentally exposed login credentials for the company's staging environment in a Google Doc set to anyone with the link can view, and the document was subsequently discovered through Google Search when a developer typed the company's domain while debugging. Pageloot responded by cutting the contractor's access, changing all affected credentials, and banning password storage in Google Docs and similar tools. The incident highlights the risks of overly permissive sharing settings on cloud documents, as anyone with the link files can become discoverable if the link appears on the public web.
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register, the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.
A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.
To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.
The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.
People share private data in online tools all the time
If there was ever an example of why you should use a password manager, this is it. Instead, the contractor typed their login details into a Google Doc, presumably to keep them handy.
Pageloot isn’t alone in dealing with this problem. Ateam, a Japanese Android game developer, left a Google Drive instance set to “Anyone on the internet with the link can view” from March 2017 until November 2023. That single misconfiguration exposed 1,369 files and personal data for 935,779 people. Ateam said it had seen no evidence anything was taken, though seven years of open access is hardly reassuring.
Scale AI, the data-labeling company central to Meta’s AI ambitions, also left 85 Google Docs with training material for Meta, Google, and xAI editable to anyone with a link. Contractors called the setup “incredibly janky”. Scale later disabled users’ ability to share managed documents publicly.
This is a trend. Three years ago, AI security company Metomic scanned approximately 6.5 million Google Drive files and found that 40.2% contained sensitive information. Just over a third were shared externally, while 0.5% were fully public.
That 0.5% might not sound like a lot, but across 6.5 million files, it still represents thousands of publicly accessible files.
This isn’t just a Google problem, though. People accidentally share sensitive information through other tools too, like the Trello project management system. Making a Trello board public makes it viewable to everyone, which was unfortunate for government users when they exposed passwords and security plans that way in 2018.
The problem is that as tools become increasingly collaborative, people can’t keep up. They make mistakes. Verizon’s 2025 Data Breach Investigations Report attributes around 60% of breaches to human factors including misconfiguration and misuse of valid credentials.
What the checkbox cost
Pageloot encountered another access-control failure involving a customer. A disgruntled former employee whose access had never been revoked used it to redirect the customer’s QR codes to a competitor’s site. It was the same root cause: nobody was watching who had access to what.
Kostabi learned his lesson, which is to keep an eye on who has access to what.
Consumers can take a few simple precautions too. Don’t store passwords or other highly sensitive information in ordinary shared documents. Use a password manager for passwords, and before hitting Share in any online service, check exactly who will be able to access what you’re sharing.
“One of the best cybersecurity suites on the planet.”
According to CNET. Read their review →
Key Takeaways
- Sensitive data stored in Google Docs with anyone with the link permissions can be indexed by Google Search.
- A Pageloot contractor exposed staging environment credentials by storing them in a publicly accessible Google Doc.
- Organizations should enforce policies against storing credentials in cloud documents with broad sharing permissions.
