Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is unauthorised disclosure?

Unauthorised disclosure exposes information to a person or destination without proper authority. It may be deliberate, reckless or accidental, and exposure does not always mean a recipient accessed the data.

Separate exposure, delivery and access

Preserve what was shared, account and process, destination, authority, message or object IDs, permissions, time and provider audits. A public link may create availability without access; a misaddressed message may be sent but rejected; delivery is not recipient use.

For links, record scope, expiry, intended recipients and access history. For messages, retain delivery and recall results.

Determine intent and ultimate recipient

Repeated sharing to one external account supports a different inference from one addressing error. The recipient account may itself be false, compromised or shared.

Screen sharing, photography and conversation may leave limited technical records, making communications, device artefacts and witness evidence more important. Report creation of exposure, completed disclosure, recipient access and intent independently.

Key takeaway

Prove unauthorised disclosure stage by stage - from exposure through delivery and access - then assess intent and recipient identity separately.

Reference: CIM-237Cyber Incidents & Offender Methods