I'm not a sysadmin; I'm an engineer studying for a certification and was looking up salary ranges for a potential future role. I searched for "salary" in the company's SharePoint and found a PDF containing the exact salaries and bonuses of employees across the company. It appears to be accessible to everyone with access to the organization's SharePoint.
I didn't bypass any permissions or intentionally search for private employee records, but I'm worried this is a serious privacy issue. I submitted an IT ticket explaining that the document seems to be broadly accessible, and now I'm anxious that I could be reprimanded simply for finding or opening it. Has anyone dealt with a similar accidental exposure, and is there anything else I should do?
4 Answers
You did the right thing by reporting it. SharePoint search normally only shows files your account already has permission to access, so this sounds like a permissions or sharing mistake rather than something you caused. Keep the ticket number and avoid opening the file again, downloading it, or sharing it with anyone. The people responsible for correcting the access settings should handle the incident.
There’s a difference between salary bands or legally published public-sector pay data and a private company exposing a document listing individual salaries and bonuses. Even where employees can discuss pay, that doesn’t necessarily mean the employer intended everyone’s exact compensation records to be searchable. Treat it as confidential information until the company confirms otherwise.
In a reasonably run company, reporting a possible exposure of sensitive employee information should be appreciated, not punished. Don’t discuss the contents with coworkers or circulate the document. If the ticket sits unanswered, you could carefully escalate it to the appropriate security, privacy, compliance, or HR contact and mention the existing ticket number.
An ethics hotline or security incident process may also be appropriate if your company has one. Use an official channel and keep the report factual—what you searched for, what appeared, and when you reported it.
I wouldn’t try to hide that you saw it or make an anonymous report after already submitting a ticket. You were looking for legitimate career information, didn’t defeat security controls, and reported the problem. If management questions you, explain exactly what you searched for, that the file appeared in normal search results, and that you stopped once you recognized the sensitivity.

Exactly. The access logs will show that you searched for and accessed something that was available to you. Reporting it gives you a clear record that you raised the issue instead of keeping quiet.