
A significant privacy incident involving Anthropic's Claude chatbot has emerged, with seemingly private conversations appearing in Google search results over the weekend. According to Forbes and Cyber Security News, the breach affected chats where users had made use of Claude's 'share' feature—which people typically use to send a record of a conversation to another person. The issue surfaced when members of a discussion channel about Claude on Reddit found that typing a specific search phrase into Google would pull up a long list of shared Claude conversations. Claude's Artifacts—interactive tools and mini apps people build inside Claude also appeared in results, with topics ranging from erotica to programming chats to work notes to fake book reviews. As per Forbes, Claude conversations are private by default, but the only chats affected were those that users had 'shared' with someone else using the platform's share button. According to Cyber Security News, users could access real Claude chats directly in Google by simply adding 'site:claude.ai/share' to their search queries, including conversations from lawyers discussing legal strategies, engineers talking through technical issues, and users being open with their personal problems.
The exposed conversations included company documents, employee performance reviews, medical information, API keys, and cryptocurrency wallet keys. As reported by Forbes, one chat—which was labeled as 'shared by Anthropic'—showed Claude generating explicit content, which goes against Anthropic's policy on erotica. The information most at risk includes medical records, clinical trial data, internal company documents, employee reviews, API keys, access credentials, and personal details such as names and addresses. According to Cyber Security News, the exposed chats ranged from mildly embarrassing to downright mortifying, depending on the conversation content. Futurism reported finding "a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers." Exposed Artifacts included code and work notes. Ravindra Baviskar, director of sales engineering at Sophos, told Business Standard that the exposure happens through features working exactly as designed, with users sharing links intending to send them to one person, but those links become permanent, crawlable web pages unless the platform blocks indexing. According to Forbes, the links do not give anyone access to a user's full account or all chats that a user has engaged in, but they still expose sensitive information when discovered through search.
According to Forbes, Anthropic used a robots.txt file to discourage search engines from crawling shared pages, but the pages reportedly did not include a noindex directive - one of the standard methods used to prevent webpages from appearing in search results. Google spokesperson Ned Adriance told WIRED that indexing shared Claude chats was Anthropic's responsibility, stating that neither Google nor any other search engine controls what pages are made public on the web. Cyber Security News reports that the glitch appears to stem from Claude's 'share' feature—if you shared a chat from Claude, it may have ended up in this searchable database. The company appears to have fixed the issue, as the links are no longer available via Google through the technique shared on Reddit, though many previously exposed chat links remained live at the time of writing. However, Cyber Security News notes that this was the second time this happened to Claude users, and at least one affected user in September denied sharing their chats, suggesting some exposed chats may have come from users who never used the share function. WIRED reports that Bing still shows 'about 612 results' if you search 'site:claude.ai/share' at the time of writing, highlighting the ongoing challenge of preventing indexing.
This incident represents a broader industry problem, as the same type of problem affected the company last year, and a nearly identical issue exposed almost 100,000 ChatGPT conversations on Google. As reported by Forbes, Elon Musk's Grok chatbot has also been affected by the same problem in the past. The 'share' feature on AI chatbots creates a unique URL for the conversation, and these links were automatically published and left open to search engines, often without users' knowledge. The fact that OpenAI, Anthropic, and xAI have each stumbled into versions of the same mistake suggests it's a problem the industry has struggled to permanently fix. Shared chats are typically more sensitive than shared documents, as people treat chatbots as a place to think out loud about work, health, and legal problems in a way they wouldn't necessarily want made public. As users increasingly share sensitive information with chatbots, incidents like these risk exposing massive amounts of private data and information. WIRED reports that Anthropic, Meta, and OpenAI all include instructions in their chatbots' robots.txt files that 'disallow' their competitors' web crawlers from accessing any part of the website where the chatbots are hosted, though Google did not address questions about this practice.
Under India's Digital Personal Data Protection (DPDP) Act, serious violations can attract penalties of up to ₹250 crore, while repeated incidents could undermine investor confidence. According to Business Standard, if personal data relating to employees or customers is exposed, it could constitute a notifiable event under the DPDP Act, leading to financial and reputational consequences. Ravindra Baviskar cautioned that such incidents often remain undetected for weeks because they do not resemble conventional cyberattacks, noting that the data simply becomes findable to anyone who runs the right search. The breach highlights the growing need for comprehensive AI data protection measures as generative AI becomes integrated into enterprise workflows. Even if users opt out of data training, companies like Anthropic will still hold chat data for 30 days after deletion, and some may have humans directly reviewing chats, something users might not consider when discussing personal issues with their AI bot. WIRED reports that Claude users can go to Settings > Privacy > Shared Chats to manage access—and keep their secret conversations private—though the pages WIRED reviewed still don't have a 'noindex' tag, meaning they could potentially show up in search engines again.