What to do if…
you sent confidential information or a file to the wrong person at work
Short answer
Contain it fast if you can, then report it immediately through your company’s IT, security, privacy, compliance, or legal incident route. Do not try to handle it quietly on your own.
Do not do these things
- Don’t pretend it did not happen or try to fix it only by deleting your sent message.
- Don’t send more sensitive details while explaining the mistake.
- Don’t argue with, blame, or pressure the recipient.
- Don’t assume there are no obligations because it was accidental; requirements can depend on the data type, contracts, company role, and state or federal rules.
- Don’t notify customers, regulators, the media, or affected people yourself unless your role and policy explicitly require it.
- Don’t destroy records that may be needed to understand what happened.
What to do now
-
Pause and record the basic facts. Write down what was sent, when it was sent, who received it, how it was sent, and whether it included personal information, credentials, health information, financial details, employee files, client information, or confidential business material.
-
Try immediate containment if you have access to do it safely.
- Use any message recall or undo-send option if your email system supports it.
- If you sent a cloud link, turn off the link, remove external sharing, or remove that recipient’s access.
- If you granted access to a folder, project, ticket, workspace, or shared drive, revoke the wrong recipient’s permission.
- If the information is in a shared system, stop adding comments or extra context until IT, security, privacy, compliance, or legal gives direction.
-
Report it immediately through your organization’s incident route. Common routes include IT, security operations, the help desk, privacy, compliance, legal, or your manager. Use clear words such as: “Possible data breach or accidental disclosure: confidential information sent to wrong recipient.”
-
Ask before contacting the recipient if your policy may control that contact. If your policy allows it, or your incident contact tells you to, send a brief neutral request asking the recipient not to open, use, forward, copy, or save the information, and to delete it and confirm deletion in writing.
-
If passwords, tokens, keys, account numbers, or access details were included, flag that as urgent. Ask IT or security to decide whether to reset passwords, revoke tokens, disable links, rotate shared secrets, or check logs.
-
Flag regulated or especially sensitive information without trying to decide the legal answer yourself. Tell privacy, compliance, or legal if the information involved health information, Social Security numbers, financial account details, payroll or benefits files, customer records, employee records, attorney-client material, trade secrets, or contract-protected information.
-
Keep a clean incident record. Save the sent-message metadata, recipient address, subject line, attachment or link names, time sent, containment actions, report time, ticket number if there is one, and any deletion confirmation. Keep it factual and minimal.
What can wait
- Deciding which state or federal law applies.
- Working out whether the event legally counts as a reportable breach.
- Writing a long apology or explanation.
- Discussing blame, discipline, performance impact, or who should have caught it.
- Designing long-term prevention changes such as labels, email rules, data loss prevention settings, training, or templates.
Important reassurance
This is a real workplace incident, but it is also a manageable one when it is reported quickly. Fast, factual action gives the right people the best chance to limit exposure, preserve necessary records, and follow the correct process.
Scope note
These are first steps only. Later decisions about risk assessment, notification, contract duties, remediation, discipline, or legal strategy may need help from your organization’s IT, security, privacy, compliance, human resources, or legal teams.
Important note
This guide is general information, not legal, medical, financial, therapeutic, or other professional advice. Follow your employer’s policies and directions from IT, security, privacy, compliance, legal, and management, especially where personal information, regulated data, health information, credentials, or contractual confidentiality duties may be involved.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.