How was that not expected? Give people somewhere to stick files that they don’t want to lose because of a hard drive crash or computer malfunction. Files that they absolutely want backed up somewhere not locally. Files that they may want to get access to while not at home… All those are going to be things like taxes, receipts, medical forms and data, scans of important documents, etc. like, that’s the point.
The article is specifically about Business Workspace accounts. The concerning part was that then about 1/3 of the sensitive files were externally shared.
To be honest, the article reads like blogspam for an up-and-coming cyber security newsletter. The “report” is just marketing for a data governance software company.
People putting sensitive documents on their personal Google drive isn’t much of a risk if they follow best security practices securing their Google account.
Plus they pick and choose numbers for a more drastic headline. "Sensitive" data is a very broad category, I don't know what criteria they used but that could be as little as someone's name being mentioned with a "todo" note. The quarter of a percent mentioned as having a "critical" issue I venture is closer to what most people think of when they read the title. Infosec consultants have a bad habit of inflating numbers until actual risks are lost in the noise.
The numbers are listed poorly and not put in the correct context, me thinks.
6.5 million documents is nothing compared to the user base of 3 billion, so that is something to keep in mind. Each number given is not clearly compared against the total user base, the total number of public documents or any other condition they listed.
Hell, I can't even tell if my guess is even accurate. It's really bad writing and I am not going to download the original report to find out more.
After I read some info on their website, I suspect the company sells security software to companies to investigate their own google drive usage. I guess they are reporting accumulated meta information their customers shared.