Handle existing exposure through a named owner
Treat discovery as a handling incident requiring triage, not a routine bulk deletion exercise. Record the system, the internal message or ticket reference, the date discovered, the type of material and the person responsible for the security response. Report those pointers through the established incident channel without attaching the sensitive material again. If the business has no named PCI or security owner, the owner of the business must assign the response and use its acquiring or payment-provider security guidance.
The responsible owner needs to determine who could access the material and where the system may have copied it. Include attachments, quoted replies, notification messages, exports and backup handling in that investigation where relevant. These are locations to check, not a claim that every support system creates every copy. Front-line staff should stop ordinary redistribution and request access containment through the owner.
Remediation must follow the actual incident and retention process. The owner should coordinate any necessary evidence handling with prompt removal of prohibited stored authentication data, and document what was done without retaining the value in the completion note. Do not improvise a new evidence archive full of card images or verification codes. Conversely, deleting the visible message without assessing exposure and other copies is not proof that the incident is resolved.
For an exposed secret or restricted key, deleting a chat does not establish that the credential is safe. Have the authorized technical or security owner assess the exposure and manage any required credential replacement through the provider's process, accounting for dependent integrations. This article does not supply a live key-rotation procedure.