Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

You emailed the wrong person. What to do before panic takes over

A wrong recipient does not have to become a major incident. The first few minutes matter: contain the mistake, report it quickly and assess the risk honestly.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
6 September 2026
READING TIME
8 min read
TOPIC
Human Security
You emailed the wrong person. What to do before panic takes over

You click Send and only then notice an unfamiliar name in the recipient field. The attachment is a contract, a salary spreadsheet or a client conversation. Your first instinct is to recall the message. Your second may be to hope nobody finds out.

Feeling embarrassed is entirely human. Hiding the mistake, however, costs the organisation its most valuable resource: time. The sooner the right people know what happened, the better the chance of containing it and making a calm risk assessment.

Contain the mistake first

If your email service offers an undo-send or recall feature, use it immediately. Do not treat “recall request sent” as proof that the message has disappeared. Whether it works depends on the mail systems involved, the recipient’s settings and whether they have already opened the message.

Next, contact the unintended recipient with a short, calm email or phone call. Ask them to permanently delete the message and its attachments and to confirm that they did not save or forward them. Do not repeat all the confidential details in your follow-up; that would only create another copy of the problem.

If you sent a file-sharing link, its owner may be able to remove or restrict access. If the message disclosed a password, access code or another live secret, have it changed. Do not erase evidence from your own mailbox before the incident team has collected the information it needs.

Report it even if the recipient promises to delete it

Tell your manager and the organisation’s designated privacy, security or IT contact. In a small business, that may be the same person. A useful initial report is factual and brief:

  • when the email was sent;
  • who received it;
  • its subject and attachments;
  • the types of data involved and approximately how many people are affected;
  • whether the recipient replied, opened the file or confirmed deletion;
  • what you have already done.

You are not expected to decide by yourself whether the incident must be reported to a regulator. The organisation must assess matters such as the nature of the data, possible consequences, the number of people affected and how trustworthy the recipient is. Your role is to provide an accurate account quickly.

Does every misdirected email have to be reported?

An email sent to the wrong person can be a personal data breach, but not every breach has to be notified to a regulator. Poland’s data protection authority explains that a controller must report a breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to create a risk to people’s rights and freedoms.

That is not a 72-hour window in which to stay quiet. The organisation needs to gather facts, limit the consequences, document its assessment and decide whether the affected people also need to be told. A message from the recipient saying “deleted, no need to worry” is helpful evidence, but it does not automatically close the incident.

What to say to the unintended recipient

A plain message is usually more useful than a long legal notice:

You received an email that was sent in error. Please do not open or forward it, and permanently delete the message and its attachments. Please reply briefly to confirm deletion.

If the recipient does not respond, threatens to publish the information or demands something in return for deleting it, do not negotiate alone. Preserve the conversation and pass it to whoever is managing the incident.

Make the next mistake less likely

The strongest safeguards go beyond telling people to “be more careful”. A process that creates a moment to check is more reliable:

  • add recipients only after the message and attachments are ready;
  • where names are similar, check the organisation and full address rather than the display name;
  • open the attachment before sending and confirm that it is the intended version;
  • for bulk messages, use an appropriate mailing tool or BCC instead of exposing the address list;
  • share sensitive documents through access-controlled links that can be revoked;
  • give people a simple, blame-free route for reporting mistakes.

If misdirected emails keep happening, examine more than the individual sender. Autocomplete, confusing file names, workload and approval steps may all contribute. Sometimes the real problem is a system that makes a predictable human error too easy.

Sources and Breachroad’s judgement

The notification threshold and timeframe above follow guidance from Poland’s data protection authority, UODO. Practical containment steps, including keeping an incident record and asking a recipient to delete the data, are consistent with the UK ICO’s first-72-hours guidance. The order of actions and process advice are Breachroad recommendations, not a substitute for a case-specific legal assessment.

For the wider response process, read “Data breach response: the first 72 hours”. If you want staff to respond confidently instead of hiding mistakes through fear, explore Breachroad’s cybersecurity awareness training and phishing simulations.

SHARE / COPY