Pageloot disclosed that staging-environment credentials were exposed after a contractor stored them in a Google Doc set to "anyone with the link can view", allowing the document to become discoverable through Google Search. The issue surfaced when a Pageloot developer, while debugging, saw a staging hostname and what appeared to be a credential string appear in Google autocomplete. The company said it revoked the contractor’s access, rotated the affected credentials, and prohibited password storage in shared collaboration platforms including Google Docs, Slack, and Notion.
The exposure highlights how misconfigured sharing settings and weak access controls in cloud collaboration tools can turn routine documentation into a security incident. Reporting on the case linked it to a broader rise in third-party and human-error-driven breaches, echoing similar exposures involving other firms and a separate Pageloot access-control lapse in which a former employee reportedly retained access and redirected a customer’s QR codes to a competitor’s site.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Verizon's 2025 Data Breach Investigations Report said around 60% of breaches involved human factors such as misconfiguration and misuse of valid credentials. The report is cited to contextualize incidents like the Pageloot exposure.
Ateam's permissive Google Drive sharing configuration remained in place until November 2023. Ateam said it found no evidence that the exposed data had been taken.
In 2018, government users exposed passwords and security plans through public Trello boards. The incident is cited as another example of accidental exposure through collaboration platforms.
Ateam left a Google Drive instance configured as "Anyone on the internet with the link can view" beginning in March 2017. The exposure ultimately included 1,369 files and personal data belonging to 935,779 people.
After 85 Google Docs containing training material for Meta, Google, and xAI were left editable to anyone with the link, Scale AI disabled users' ability to share managed documents publicly. No explicit date is provided for either the exposure or the remediation.
In a separate access-control failure, a disgruntled former Pageloot employee retained access that had not been revoked and used it to redirect a customer's QR codes to a competitor's site. The incident is described as another consequence of poor access governance at Pageloot.
After discovering the exposed Google Doc, Pageloot revoked the contractor's access and changed every affected credential. The company also banned password storage in Google Docs, Slack, Notion, and other shared workspaces.
At an unspecified date, a Pageloot contractor stored staging-environment credentials in a Google Doc set to "anyone with the link can view," and the document became discoverable through Google Search. A Pageloot developer noticed the exposure while debugging after Google autocomplete surfaced a staging hostname and an apparent credential string.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourceverizon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.