Nine File Sharing Mistakes That Quietly Leak Your Data

Published 2026-03-28 · Updated 2026-06-18 · 8 min read · By the SENDIT team

Most data exposure is not hacking. It is ordinary sharing habits repeated for years. Here are the nine most common ones and what to do instead.

When people imagine a data leak they picture an attacker. In practice, the overwhelming majority of exposure is self-inflicted and undramatic: a link that never expired, a folder shared with the wrong person, a filename that revealed more than the file. These are habits, not incidents, which is good news — habits can be replaced.

1. Links that never expire

A share link created for a fifteen-minute need and left live for four years is the single most common exposure in ordinary work. Nobody audits their old shares. Fix it by defaulting to expiring transfers, and by scheduling one annual pass through your cloud drive's shared-links list to revoke anything you no longer recognise.

2. Sharing the whole folder to send one file

Granting folder access is faster than locating the file, so people do it. But folders grow. The person you gave access to in March now sees everything added in September. Always share the specific file, and if you must share a folder, create a new one containing only what is intended.

3. Descriptive filenames

Filenames travel further than contents. They appear in notifications, chat previews, log files and backups. A file called divorce-settlement-draft-final.pdf discloses the sensitive fact before anyone opens anything. Rename to something neutral before sharing; you can tell the recipient what it is separately.

4. Sending the file and the password together

A password-protected archive followed immediately by a message containing the password in the same thread provides no protection whatsoever. Whoever can read one message can read both. The password must travel on a different channel: file over email, password over a call or a separate messaging app.

5. Forgetting the metadata inside files

Documents carry author names, edit history, tracked changes and comments. Photographs carry GPS coordinates, device identifiers and timestamps. Spreadsheets carry hidden rows and other worksheets people forget exist. Before sending externally, export to a flattened format such as PDF, strip location data from images, and open the file yourself with fresh eyes to check what is visible.

6. Using personal accounts for work files

It feels harmless and it creates a permanent tangle. Work data ends up outside organisational control, invisible to security policy, and still present after you leave. It also mixes with personal data in ways that make any future request for deletion or disclosure genuinely difficult to satisfy. Keep the two separate even when it is inconvenient.

7. Trusting chat platforms as an archive

Files sent in group chats persist for every member, including people added afterwards in some platforms, and remain on every participant's device. Group membership drifts over months. A file shared with six people in January may be visible to twenty by June. Treat any group chat as a semi-public space.

8. Ignoring the recipient's side

Your careful transfer ends the moment the file lands in a downloads folder on an unencrypted laptop that is shared with a family member. You cannot control this fully, but you can influence it: ask the recipient to delete after use, avoid sending more than they need, and prefer viewing over downloading when the content is highly sensitive and the tool supports it.

9. Sending more than is required

The most under-used control is redaction. If someone needs to verify your address, they do not need a full identity document with a number on it. If a colleague needs one quarter of sales figures, they do not need the entire customer export. Trimming what you send reduces the consequences of every other mistake on this list simultaneously.

Replacing the habits

  • Default to expiring, code-gated transfers instead of permanent links.
  • Share files, never folders, unless the folder is purpose-built.
  • Neutralise filenames before sending.
  • Split the payload channel from the secret channel, always.
  • Flatten and strip metadata for anything leaving your organisation.
  • Keep work and personal accounts separated.
  • Assume group chats are permanent and semi-public.
  • Send the minimum necessary, redacted where possible.
  • Confirm receipt, then close the share early.

None of these require tooling changes or budget. They require deciding once, and then doing the slightly slower thing consistently. Over a career, that difference is the entire gap between people who have a leak story and people who do not.

Running a fifteen-minute audit

Habits change slowly, but you can remove years of accumulated exposure in a single sitting. Open your main cloud drive and find the list of items shared with a link. Revoke anything you do not immediately recognise; if it turns out to be needed, someone will ask and you can re-share deliberately. Then check the list of people with access to your top-level folders and remove anyone who has left, finished their project, or was added for a single task.

Do the same for connected third-party applications, which quietly hold read access to entire drives long after you stopped using them. Fifteen minutes once a year removes more risk than most security software, and it costs nothing.

Finally, write down what you found. Patterns repeat, and knowing that you always over-share folders or always forget contractors tells you which of the nine habits above to work on first.

More from SendIt