You sent a file to the wrong person: what can be undone and what cannot

The first minute is worth more than everything after it. Before reading further: if the file is on a share link you control, revoke the link now, then come back.

Updated:

The window, by channel

ChannelCan you pull it back?
Gmail"Undo send" only, within 5–30 seconds, and only if you enabled the longer window in Settings
Outlook / Microsoft 365Recall works only inside the same organisation, only if the message is still unread, and frequently fails silently
Any other emailNo. Once it has left your server it is gone
WhatsApp / Telegram / Signal"Delete for everyone" within a limited window — recently a couple of days on WhatsApp; the recipient may already have the file saved
Slack / TeamsYou can delete your own file, and it disappears for everyone who has not downloaded it
Cloud drive link (Drive, OneDrive, Dropbox)Revoking sharing works — completely, if nobody has downloaded it yet
Transfer service with a link or codeDepends on the service: some let you delete the transfer, all of them expire it eventually

The pattern: anything that leaves a copy on your infrastructure can be revoked; anything that pushed a copy to theirs cannot. An email attachment is a copy that has already arrived. A share link is a pointer you still hold, which is exactly why revoking it works — and why a link's lifetime matters so much in the first place.

Advertisement

What to do, in order

  1. Revoke or delete first, read the room second. Every minute reduces the chance the file is still only on your side. Do not compose an apology before you have pulled the link.
  2. Find out whether it was opened. Cloud drives show access; some transfer services show whether a download happened. This single fact decides whether the rest is cleanup or a real incident.
  3. If the file contained credentials, rotate them now. API keys, passwords, tokens, a database dump with hashes. Assume compromise; rotation costs an hour, the alternative does not have a fixed price.
  4. Tell the recipient plainly and ask them to delete it. This is not a legal remedy and does not bind anyone, but most misdeliveries go to a colleague or a neighbouring address, and most people simply delete it when asked. Ask them to empty the trash too.
  5. If the file held other people's personal data, escalate rather than handle it quietly. Under GDPR a personal-data breach is notifiable to the supervisory authority within 72 hours; Türkiye's KVKK has an equivalent 72-hour expectation. That clock starts when you become aware, not when someone decides how serious it is — and quietly deleting a link is not a defence.

What cannot be undone, no matter what the button says

Making the next one cheaper

The structural fix is not to be more careful — everyone is already trying to be careful. It is to send files in a form where a mistake stays revocable.

More guides

Try SendMyFile

Encrypt a file in your browser and hand it over with a 9-digit code. No account, and it deletes itself.

Try SendMyFile