Skip to main content
CybersecuritySocial Engineering

IT Department Exposes Login Credentials on Sticky Notes

Laptops with sticky notes on a conference room table, surrounded by scattered papers and chairs.

A contractor walked into a conference room, photographed sticky notes stuck to a row of laptops, and later used those captured login details to access proprietary planning documents on shared drives.

How the exposure unfolded

Marc Bishop, director of business growth at Wytlabs, recounted a chain of simple decisions that led to the compromise. A firm moving offices decided to reissue old laptops to new users and — to “make life easy for the recipients” — placed sticky notes on each machine listing the employee name and the initial login credentials. While facilities finished preparations, the laptops sat in a conference room where anyone with access could enter and read the notes. A contractor did exactly that: they photographed the sticky notes, later logged in remotely, and accessed proprietary data.

Where routine policy collided with routine shortcuts

Bishop’s client company, the column reports, was not lax on paper policies: it maintained a strong password policy and required users to take security training. The failure was procedural and physical rather than doctrinal. The Register’s PWNED column highlights the irony that the group charged with guarding the henhouse — the IT department — was the proximate cause of the leak by putting credentials “in the precisely wrong place.” The column observes that even an IT team should not have users’ passwords visible, because someone within IT could become a threat as well as outsiders.

What the intruder got and how

The Register’s account is specific about the outcome: the unauthorised actor, described as a non-employee contractor, photographed the sticky notes and subsequently logged in remotely. That access yielded “all kinds of proprietary data, including planning documents that were sitting on shared drives.” The photographs provided a simple, high-fidelity avenue to valid credentials and therefore to files behind authenticated access controls.

Simple, recommended fixes the column stresses

  • The Register’s PWNED column bluntly advises against placing usernames and passwords on paper or other visible surfaces. “Password security is paramount,” the column states.
  • For new accounts, the column recommends sending initial credentials “through an encrypted channel” and ensuring “only the intended recipient can view the temporary password.”
  • It also underscores a basic operational point: do not rely on physical obscurity (a closet or a support-staff-only shelf) as the only control for sensitive secrets — visibility is the risk.

What this means for IT teams, facilities staff, and contractors

  • IT teams: A well-written password policy and training can be undone by one careless delivery method. The column’s prescription is to stop using visible notes for credentials and to deliver initial passwords by encrypted, recipient-limited channels.
  • Facilities staff: Temporary storage choices matter. Staging equipment in shared spaces like conference rooms can expose credentials to anyone who has physical access during a move or renovation.
  • Contractors and non-employees: The incident shows how an individual with casual physical access can capture and later exploit exposed credentials; photographic capture of paper notes was the enabling technique in this case.

The lesson is stark and particular: a team charged with protecting systems converted convenience into an access vector. The Register’s report leaves little mystery about the mechanics — visible credentials, photographs taken in an accessible conference room, and later remote login — and it closes with a pointed operational fix: stop putting secrets where passersby can see them and use encrypted, recipient-bound channels for initial credentials. The unanswered practical step for the affected firm is now plain and procedural — change how initial credentials are handled before the next office move.

Source: The Register — IT department put sticky notes on the laptops to help employees log in