AI

Shared Claude Chats Turned Up in Google Search Results

Claude share links were indexed by Google, exposing medical reports, student contact details and confidential company documents. Anthropic fixed it within days, but the lesson is about what a share button actually does.

Faruk TalmaçJuly 28, 20263 min read3 views
Shared Claude Chats Turned Up in Google Search Results

Ask most people what the share button in an AI chat app does and they will describe email: a private link, sent to one person. Ask again after last weekend and the answer gets more complicated.

A Reddit user noticed on Saturday that Claude share links were being indexed by Google. 404 Media reported it Monday morning. For anyone who had ever generated one of those links, it meant strangers could read the conversation by typing a search query.

Sensitive material sitting in plain search results

According to TechCrunch, the indexed conversations included a detailed medical patient report, clinical trial results, the names and phone numbers of primary school students, confidential company documents and employee reviews.

Anthropic did not say how many chats were affected. For scale: a comparable incident last year exposed roughly 600 conversations, and when the same thing happened with ChatGPT, around 100,000 conversations became searchable. This is a category of failure the industry keeps repeating rather than a novel one.

Anthropic's answer, and its gap

The company's position is that share links were always designed to be public, and that where a user posts the link is the user's decision. On the technical side the problem was addressed by Monday afternoon; testing later that day showed the results had been pulled from search.

The explanation holds up technically and falls short practically. If a feature publishes a public web page, the interface has to say so in language the person clicking understands. Someone sharing a conversation believes they generated a link. They did not think they published a page. Under most data protection regimes, that difference decides whether an accident becomes a reportable breach.

Three checks worth running today

The uncomfortable part is that no vulnerability was involved. Most data exposure in AI tools comes from products working exactly as designed, used by people who misread what a button meant. So the fix is procedural, not technical.

  • Audit what you already shared. In Claude, Settings → Privacy → Shared Chats lists the public links you have created and lets you revoke them. Run the equivalent check in ChatGPT and Gemini while you are at it.
  • Give teams a sanctioned way to share. Copy-paste, screenshots, or the project and workspace features in business plans keep conversations inside your tenancy. Public links should not be the default path for internal collaboration.
  • Agree on what never gets pasted. Customer names, national ID numbers, health data, contract text. A masking habit at the input stage shrinks the blast radius of every future incident of this kind, including ones nobody has thought of yet.

Security programs tend to focus on the sophisticated attack. This week's reminder is that the expensive mistakes usually come from the most ordinary button on the screen.

Sources: TechCrunch, The Decoder

Share This Article

Faruk Talmaç

Written by

Faruk Talmaç

Co-Founder & Editor

Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk