Can a shared link be forwarded to somebody else?¶
Yes. A shared link can usually be forwarded, copied or posted elsewhere unless the service restricts it to named users or an organisation.
The dangerous assumption is that the person who received the link originally was the only person who could use it.
What this means in practice¶
A link set to “anyone with the link” may be opened by anybody who obtains it. A link restricted to named accounts may still be forwarded, although the new recipient may be unable to access it without the required sign-in.
Links can also be copied into messages, documents, forums, notes or browser synchronisation.
This matters for attribution. The original sender, intended recipient and actual user may all be different people.
Investigators should identify the link permissions, whether authentication was required, the creation and expiry times, and whether the link was later changed or revoked.
A forwarded link may also be accessed by automated security tools or preview services before the human recipient opens it.
Where the link remains live, preserve its settings and usage records before altering or revoking it where operationally possible.
What this does not show on its own¶
Access logs may show accounts, IP addresses, times and browser or device information, but those records do not automatically identify the person behind each event.
What to do next¶
Check communications and provider sharing records to establish who received or forwarded it.
Do not assume that one access event corresponds to one person. The same link may be used several times from several devices or shared connections.
Key takeaway
A shared link is transferable unless access controls prevent it, so separate the creator, original recipient, later recipients and actual users in the evidence.