PanicStation.org
us Technology & digital loss

What to do if…
a private file or folder is shared publicly through a link you did not create

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not forward or repost the link. Contact the apparent owner through a separate trusted channel and, if you control the account, use the provider’s official app or website to remove public access and secure the account.

Do not do these things

  • Do not send the link to other people to ask whether they can open it.
  • Do not enter a password, payment information, or verification code through the unexpected link.
  • Do not download, edit, move, or delete the material unless you are authorized to manage it.
  • Do not rely on changing a password alone; the link may have separate sharing controls.
  • Do not contact a suspected sender through an account or message channel that may be compromised.
  • Do not copy sensitive contents into an email, support form, or public post when reporting the exposure.

What to do now

  1. Stop the link spreading. Keep it out of group chats, social media, forwarded messages, and public reports.

  2. Contact the apparent file owner through a phone number, email address, or account you already trust. Tell them where you found the link without repeating sensitive information from the file.

  3. If the file or folder is in an account you control, open the provider’s official app or type its known website address yourself. Review the sharing settings and disable public access, restrict the link, or remove unknown collaborators where those controls are available.

  4. Record only what is needed to report the problem: the URL, the hosting service, when you found it, and where it appeared. A screenshot of the sharing or landing page may help, but avoid capturing or duplicating sensitive contents.

  5. If it is a work, school, client, or organization file, alert the appropriate IT, security, privacy, or data owner immediately. Give them the link and basic circumstances, then follow their incident instructions.

  6. If you cannot restrict the link or reach the owner, look for the hosting service’s official privacy, safety, or abuse-reporting route. Report that the material appears to have been shared publicly without authorization.

  7. If there are signs that an account was accessed without permission, use a device you trust to change its password, sign out other sessions, check its recovery email and phone number, and enable multi-factor authentication if available. Change reused passwords on other accounts as well.

  8. If the exposed material contains passwords, access keys, or recovery codes, change or revoke them promptly. If it contains a Social Security number, bank or credit card details, government identification, or medical insurance information, use IdentityTheft.gov and contact the relevant institution for steps based on what was exposed.

What can wait

You do not need to identify who created the link, count every possible viewer, decide on legal action, or prepare broad notifications right now. For work, school, client, or organization material, alert the responsible team and let it assess any later notification or reporting duties.

Important reassurance

A publicly accessible link is serious, but the link’s existence does not by itself show who viewed or downloaded the material. Restricting access, alerting the responsible person or organization, and securing affected accounts are useful immediate steps.

Scope note

This guide covers immediate containment only. Later takedown requests, organizational notifications, identity-theft recovery, or legal questions may require help from the service provider, an IT or privacy specialist, the affected institution, or an attorney.

Important note

This is general information, not legal, cybersecurity, privacy, identity-theft, or other professional advice. The appropriate response may depend on the file service, the information exposed, who owns it, and whether an organization is responsible for it.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us