Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Staff Have Shared Documents With 'Anyone With the Link' for Years. How Do We Find Out What Is Exposed and Lock It Down?
Problems We Solve

Staff Have Shared Documents With 'Anyone With the Link' for Years. How Do We Find Out What Is Exposed and Lock It Down?

Company files shared publicly through open links in SharePoint, Google Drive or S3? How SpiderHunts finds exposed files, closes them and sets safer defaults.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Files shared with 'anyone with the link' stay open long after the reason for sharing has gone, and cloud storage buckets can be left public by mistake. SpiderHunts audits sharing across Microsoft 365, Google Workspace and cloud storage such as Amazon S3, closes links that should not be public, changes the default sharing settings, and sets up alerts and expiry so new public links do not build up again.

Someone needed to send a price list to a prospect, so they shared the folder with anyone who has the link. An accountant needed the year-end files, same again. A developer set up a storage bucket for website images and made it public, and later someone started putting customer exports in it too. A contractor was sent a SharePoint link to the HR folder to fix one document.

Each of those decisions made sense on the day. Nobody went back to close them. Now nobody knows how many files anyone on the internet could open with the right link.

  • The default sharing setting in the tool allows anyone-with-the-link sharing, so it is the easiest option.
  • Sharing outside the company properly (named guests, access requests) feels slower than copying a link.
  • Links do not expire unless someone sets an expiry.
  • Folders are shared rather than single files, so everything added later is shared too.
  • Cloud storage buckets are created by developers with public access for one purpose and reused for others.
  • When staff leave, the links they created stay open.

The folder point is the one that tends to surprise people. A folder shared publicly for one document keeps sharing every new document added to it, years later.

What is at risk

Exposed itemWhy it matters
Customer lists and exportsPersonal data open to anyone who finds or is forwarded the link
Contracts, pricing and proposalsCommercially sensitive information in competitors' reach
HR and payroll filesStaff personal data exposed
Public storage bucketsAutomated scanners look for open buckets and download their contents
Forwarded linksA link in one email can end up anywhere

Links are not as private as they seem. They get forwarded, pasted into chats, saved in browser histories and sometimes indexed. And an exposure of personal data can carry reporting obligations under data protection law, which is a far worse way to find out about it.

How we find and close public sharing

  1. Inventory where files live: SharePoint and OneDrive, Google Drive, Dropbox or Box, and cloud storage such as Amazon S3 or Azure Blob Storage.
  2. Report on external sharing. We use the admin reporting in Microsoft 365 and Google Workspace, and the cloud provider's access analysis for buckets, to list every file and folder shared publicly or with outside accounts, with who shared it and when.
  3. Review with the owners. Each exposed item is checked with the person or team responsible: keep it shared, switch it to named people, or close it.
  4. Close what should not be public, starting with anything holding personal or sensitive data, and block public access at the account level for cloud storage that never needs it.
  5. Change the defaults. Default sharing becomes internal or specific people, anyone-with-the-link is restricted or given an automatic expiry, and external sharing for sensitive sites and folders is switched off.
  6. Give people an easy safe route: guest access for regular partners, and a clear way to share one file with one person, so nobody feels the need to work around the rules.
  7. Keep watching. Alerts for new public links on sensitive areas, and a regular review of external sharing, so it does not build up again.

We keep this proportionate. Many public links are harmless, such as marketing brochures. The aim is to close what matters without stopping people sharing the things they need to.

After the clean-up

You know what is shared outside the business and why. Sensitive files are no longer one forwarded link away from a stranger. New sharing defaults to named people, and public links expire on their own. Storage buckets that should be private are blocked from being made public by accident. And when someone leaves, their shared links are part of the leaver checklist.

Could this be you?

  • Staff routinely share files with anyone who has the link.
  • Nobody has reviewed external sharing in your Microsoft 365 or Google Workspace.
  • Whole folders have been shared with customers, suppliers or contractors.
  • Developers have created cloud storage buckets with public access.
  • Former employees' shared links have never been checked.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Will closing links break things people rely on?

It can if done blindly, which is why we review exposed items with their owners first and switch essential ones to named access instead of simply closing them.

Can we see who has opened a public link?

Often only partly. Audit logs in Microsoft 365 and Google Workspace record some access, depending on your licence and settings. This is one reason to close open links rather than rely on checking them.

Do we need extra software for this?

Usually not to start. The admin tools in Microsoft 365, Google Workspace and the cloud providers cover the audit and settings. Extra tools can help in larger or regulated setups.

What if we find personal data was exposed?

Close it first, then take advice on whether it needs reporting under data protection law. We can help work out what was exposed and for how long, where the logs allow.

Keep reading

More on Problems We Solve

Start here

Not sure what is shared publicly?

Tell us which file storage your business uses, such as SharePoint, OneDrive, Google Drive, Dropbox or S3. We will help you find what is open to anyone and close it without breaking the sharing people rely on, and if your settings are already sound, we will tell you.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →