Are we talking about potentially stolen/illegal/faked documents being leaked online somewhere? In that case I’d say if you’re an employee with access, follow company guidelines. If this is just public in the internet because somebody was too stupid to secure their MongoDB instance or something though, get behind a reasonably secure non-logging VPN and delete that shit. Don’t poison it though, that’ll make things worse in ways you can’t predict.
If this is data that looks like it’s real, and classified/national security related though, call the FBI immediately and let them handle it. Go no further than that.
you could be subject to investigation as a system contact.
if you truly believe you have evidence of crime make a report.