What to do if…
a private file or folder is shared publicly through a link you did not create
Short answer
Use the storage service’s official app or website to restrict or disable the public link, then secure the account that controls the file or folder. If it belongs to an employer, school or another organisation, contact its IT or security team immediately.
Do not do these things
- Do not forward the public link to ask other people whether it works.
- Do not sign in through an unexpected email or message about the file.
- Do not delete the file or folder before checking whether access can be restricted.
- Do not erase recent activity, alerts or sharing records before noting what happened.
- Do not contact an unknown person who may have created the link.
- Do not delay notifying the responsible organisation if other people’s personal information may be exposed.
What to do now
-
Open the cloud storage service through its official app or by typing its usual website address yourself. Find the affected file or folder and change public or anyone-with-the-link access to restricted access. Remove unfamiliar links, accounts or permissions.
-
Note the file or folder name, when you found the link, the access setting, unfamiliar accounts shown and any recent activity displayed by the service. Take screenshots if this can be done without exposing or circulating the contents.
-
Check recent sign-ins, active sessions, connected apps, devices and security alerts for the account. Sign out sessions and remove apps or devices you do not recognise.
-
Change the account password through the service’s official settings if you suspect unauthorised access. Use a password that is not used for another account, and turn on two-step verification where available.
-
Check the email account linked to the storage service, particularly if its password was reused or there are unfamiliar password-reset messages. Review recent activity and secure that account as well.
-
If the file or folder belongs to a workplace, school, charity, client or other organisation, contact its IT, security or data-protection contact now. Give them the affected item, the time you discovered it and the containment steps already taken.
-
Check what type of information was exposed without forwarding it. If it contains passwords, access keys, payment details or identity documents, contact the relevant account provider, bank or issuing body through an official route.
-
If it contains other people’s personal information, notify the organisation responsible for that information promptly so it can assess, record and respond to the breach.
-
Contact the storage provider through its official support or security route if you cannot disable the link, regain control of the account or stop further unauthorised changes.
-
If money has been taken, contact your bank immediately. Use the UK government cyber-incident signposting service if you need to identify an appropriate reporting route.
What can wait
You do not need to identify who created the link, determine exactly how many people opened it or make every reporting decision before restricting access and securing the account. Complaints, replacement documents and longer-term security changes can wait until the immediate exposure is contained and the responsible provider or organisation has been notified.
Important reassurance
An unknown public link does not by itself show that anyone opened, downloaded or copied the file. Restricting access quickly, securing the related accounts and notifying the responsible organisation can reduce further exposure while the activity is reviewed.
Scope note
This guide covers immediate containment and account-protection steps only. Investigation, recovery, regulatory assessment and decisions about affected individuals may require the storage provider, the responsible organisation, a data-protection specialist or a cyber-security professional.
Important note
This is general information, not legal, data-protection, cyber-security or other professional advice. Reporting duties depend on who controls the information, what was exposed and the risk created; organisations should check current ICO guidance or obtain appropriate professional advice.
Additional Resources
- National Cyber Security Centre — Respond to a cyber attack overview
- National Cyber Security Centre — Top tips for staying secure online
- National Cyber Security Centre — Top tips for staying secure online
- National Cyber Security Centre — Use a strong and separate password for your email
- GOV.UK — Where to Report a Cyber Incident
- Information Commissioner's Office — What steps should I take if I have experienced a data breach?
- Information Commissioner's Office — Personal data breaches
- Information Commissioner's Office — UK GDPR data breach reporting (DPA 2018)
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.