What to Do If You Accidentally Send a Confidential Email to the Wrong Person
Sent sensitive data to the wrong inbox? Follow this order: recall, report, then contact the recipient, and see what actually determines the risk.
Sent sensitive data to the wrong inbox? Follow this order: recall, report, then contact the recipient, and see what actually determines the risk.
If you send a confidential email to the wrong person, act in this order: try to recall it, assess exactly what was exposed and to whom, notify your security or privacy team immediately even if the recall works, and only then contact the recipient. Reporting first protects the organization; apologizing first without reporting is how a contained mistake becomes an unreported breach.
Table of Contents
ToggleMisdirected email is not a rare slip. The UK Information Commissioner’s Office (ICO), the regulator that tracks reported data security incidents across the country, has found emailing data to the wrong recipient among the single most common categories of reported non-cyber incident for years running, accounting for 16 to 21 percent of all ICO-reported incidents in recent quarters. Verizon’s Data Breach Investigations Report classifies this under its Miscellaneous Errors pattern, and it remains a stable, recurring share of confirmed breaches every year the report runs. This is not exotic. It is autocomplete picking the wrong contact, a reply-all instead of a reply, or a legacy distribution list nobody pruned.
How human error contributes to security risk explains why severity depends entirely on what left the building and who received it. A misdirected meeting reminder is a non-issue. A misdirected spreadsheet of customer records, health information, or a client’s legal file is a reportable data breach the moment it leaves your outbox, whether or not the recipient ever opens it.
Move in this order when you catch a misdirected email, not the order that feels natural.
Try to recall or unsend the message first. Gmail’s Undo Send window is measured in seconds; Outlook’s recall only works reliably within the same Exchange organization and fails silently if the recipient has already opened the message. Do not assume a recall succeeded. Check.
Report it internally before you contact the recipient. This is the step most people skip, because apologizing to the recipient feels like the responsible thing to do first. It is not. Your security, privacy, or compliance team needs to start the clock on assessment and, if required, regulatory notification, and they cannot do that if they hear about the incident after you have already handled it yourself. Reporting a near miss that turns out to be low-risk costs a five-minute conversation. Failing to report an incident that turns out to be a reportable breach costs the organization its notification window and costs you the appearance of having tried to hide it.
Only after reporting should you contact the recipient, and coordinate that contact with your security team rather than freelancing an apology that might undercut a legal notification requirement later.
Discover how Threatcop protects your workforce from modern cyber threats.
Two questions decide how serious a misdirected email actually is: what kind of data was in the message, and who received it.
Personally identifiable information, health data, financial account details, credentials, or anything covered by a confidentiality agreement raises the severity immediately, which is the same logic behind general email security best practices. An internal typo, where the wrong recipient is still inside the organization and bound by the same policies, is a lower-risk event than data landing at an external domain, a competitor, or a journalist. The 2018 Commonwealth Bank of Australia incident is the textbook case: staff meant to send internal mail to cba.com.au and instead sent it to cba.com, an unrelated US company’s domain, exposing over 10,000 customers’ data to a party with no relationship to the bank at all.
This is the same assessment work described in information security risk management. Attachments deserve a separate check. A message body can be relatively harmless while an attached file carries the actual sensitive payload, and people scanning quickly for what to escalate often check the email text and skip the attachment.
Report every misdirected email that involves personal data leaving its intended boundary, even ones that feel like near misses. Organizations track these reports to spot patterns, such as one employee repeatedly hitting reply-all on a distribution list, that a single incident would never reveal on its own.
Organizations with a documented incident reporting culture catch these patterns faster. A 2023 case from the UK’s ICO shows why speed and honesty matter more than optics. NHS Highland emailed 37 people accessing HIV services using CC instead of BCC, exposing every recipient’s email address to every other recipient; one person recognized a former partner on the list. The ICO’s reprimand centered on the failure of a basic safeguard, not on malice, and the health board’s response, and its documented remediation plan, directly shaped how the regulator handled it. Where personal data is involved, UK GDPR and equivalent regimes elsewhere can require notification to a regulator within a fixed window, commonly 72 hours, which is only achievable if the report reaches security or privacy staff immediately rather than after an employee has quietly tried to resolve it alone.
For the organization, a confirmed data breach carries the costs the data above implies: regulatory reporting obligations, potential fines, and reputational exposure with the client or individual whose data was exposed. Outbound email errors have been trending upward as organizations move more sensitive work to email and messaging tools, which is exactly the environment that makes a single autocomplete mistake more consequential than it would have been a decade ago.
For the individual who made the mistake, the honest answer is that outcomes vary by how the incident is handled, not just by the fact that it happened. An organization with a documented, blame-aware reporting process typically treats a promptly reported, honest mistake very differently from a concealed one discovered later. This is also the practical argument for reporting immediately: it is the version of events that puts you on the right side of that distinction.
No amount of vigilance eliminates human error entirely, which is why the fix is a combination of habits and safeguards rather than a single rule.
| Control | What it does | Who it depends on |
|---|---|---|
| Pause before sending to a group or an autocompleted contact | Catches the wrong-name and reply-all mistakes before they leave the outbox | The sender, every time |
| Delay-send or a short send window | Gives a few seconds to catch an obvious mistake, mirroring Gmail’s Undo Send | Email client configuration |
| Separate distribution lists from ad hoc CC fields for anything sensitive | Removes the CC-instead-of-BCC failure mode that caused the NHS Highland breach | IT and the sender |
| A named, low-friction internal reporting channel | Makes reporting a 30-second action rather than an uncomfortable escalation | The organization’s security team |
| Role-based training on what counts as sensitive and where the fast-path mistakes happen | Builds the pause habit specifically around the moments that cause real breaches | Ongoing training, not a one-time module |
That last row is where role-based training earns its place. Generic reminders to “double check before you send” get ignored because they ask for constant vigilance on every email, which nobody sustains. Threatcop’s TLMS instead delivers short, role-based refreshers aimed at the specific moments that cause misdirected-email incidents, like handling a client distribution list or forwarding a document with an attachment, rather than a single annual module that tries to cover everything at once.
A misdirected email is rarely malicious and almost always fast: one wrong autocomplete entry, one reply-all, one CC that should have been a BCC. The organizations that handle it well are not the ones with zero mistakes. They are the ones where reporting is immediate and unremarkable, and where training targets the specific moments that cause real incidents rather than asking employees to be perfectly careful on every message they send. See how role-based training can build that habit on Threatcop’s security awareness training platform.
Sometimes. Gmail’s Undo Send only works for a short delay window, typically up to 30 seconds, that must be enabled beforehand. Outlook’s recall feature only works reliably within the same Exchange organization and fails if the recipient has already opened the message, so never assume a recall succeeded without checking.
Yes. Report it regardless of what the recipient says they did with it. Security and compliance teams need the report to assess risk and meet any regulatory notification obligations, and a recipient’s assurance that they deleted the message is not something the organization can verify or rely on for its own reporting duty.
A misdirected email can be a data breach. If the email contained personal data, confidential business information, or anything covered by a confidentiality agreement and reached someone not authorized to see it, most privacy regulations treat that as a personal data breach requiring assessment, and in some cases formal notification.
With a misdirected email, the biggest mistake is contacting the recipient before reporting internally, since that order determines whether the organization treats it as an incident with a documented process or a problem an individual tried to fix alone. It feels like the responsible first step, but it delays the organization’s assessment and notification clock and can complicate a legal response that needs to be coordinated rather than handled informally by the person who made the mistake.
Using CC instead of BCC exposes every recipient’s email address, and by extension their association with whatever the message is about, to every other recipient. That single field choice caused the ICO’s reprimand of NHS Highland over an email to people accessing HIV services, where one recipient recognized a former partner on the list.

Director of Growth
Naman Srivastav is the Director of Growth at Threatcop, where he leads customer-facing and product marketing teams. With a self-driven mindset and a passion for strategic execution, Naman brings a competitive edge to everything he does — from driving market expansion to positioning Threatcop as a leader in people-centric cybersecurity.
Director of GrowthNaman Srivastav is the Director of Growth at Threatcop, where he leads customer-facing and product marketing teams. With a self-driven mindset and a passion for strategic execution, Naman brings a competitive edge to everything he does — from driving market expansion to positioning Threatcop as a leader in people-centric cybersecurity.
Cybersecurity mindfulness helps employees catch AI-generated scams before they click. See the research behind it and how to build...
A confidential email lands in your inbox by mistake. See the right order of steps to take, when to...
AI-written phishing has no typos left to catch. See why manufactured urgency is now the most reliable red flag,...
Table of Contents
×