cd /news/ai-products/anthropic-says-your-leaked-claude-ch… · home topics ai-products article
[ARTICLE · art-77478] src=thenextweb.com ↗ pub= topic=ai-products verified=true sentiment=↓ negative

Anthropic says your leaked Claude chats are working as intended

Anthropic says its Claude chat-sharing feature is working as intended after Google indexed thousands of shared conversations, including medical records and children's phone numbers, because the company did not use a "noindex" tag to block search engines. Anthropic spokeswoman Amie Rotherham told TechCrunch that the company gives users control over sharing and does not share chat directories with search engines, placing responsibility on users who make content publicly accessible. The incident mirrors previous cases at OpenAI and Anthropic itself, where shared chats became searchable on Google.

read4 min views1 publishedJul 28, 2026
Anthropic says your leaked Claude chats are working as intended
Image: Thenextweb (auto-discovered)

Type the right query into Google over the weekend and you could read strangers’ conversations with Claude. Some held medical records. Some held company files and children’s phone numbers. The chats were not hacked or leaked in any technical sense. Users had shared them through a Claude feature built for that. Search engines then indexed the pages like any other public link.

Anthropic’s position is that nothing failed. The system, it says, is working as intended.

How it surfaced #

A Reddit user flagged it on Saturday. The search operator “site:claude.ai/share” returned a long list of shared Claude chats. 404 Media first reported it on Monday, and the rest of the tech press followed within hours.

Claude conversations are private by default. Only shared ones were affected. Sharing creates a snapshot of the chat at its own public web address, meant for a colleague or a small group.

The problem is what “public” turned out to mean. A simple “noindex” tag tells search engines to leave a page out of results. It does not appear Anthropic used one.

What was in them #

The exposed material was not trivial. Futurism reviewed the results through Google. It found a detailed medical report on a named patient, clinical-trial results listing patient names, and documents holding the names and phone numbers of primary-school-aged children.

Other cases were worse for being ordinary. Reddit users cited a person building a crypto wallet who exposed its keys. Another was a lawyer asking Claude whether they had to self-report a breach of professional conduct.

Claude Artifacts were caught in the same net. These are the interactive apps and documents people build in the tool. Internal dashboards and project plans with client data turned up alongside the chats.

Anthropic’s answer #

Asked what happened, Anthropic did not describe a fix. It described a design.

“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” spokeswoman Amie Rotherham told TechCrunch.

“These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible.”

The company added that links only reach search results once a user posts them somewhere a crawler can see. In effect, it placed the responsibility with the people who pressed share.

The comparison that hurts #

That defence runs into an obvious counter-example. Google Docs offers a near-identical share feature. Those documents do not end up searchable on Google.

The difference is the missing instruction to search engines. Google’s spokesperson Ned Adriance told TechCrunch that site owners hold the crawl and index controls, and that Google respects them. The choice not to use them sat with Anthropic.

Underneath is a gap between two definitions of consent. Anthropic is technically right that sharing makes content public. The harder question is whether the person sharing a patient file understood they were publishing it to the open web.

It has happened before, at every lab #

This is not new, which is what makes it striking. Forbes reported almost the same thing last September. Google had indexed just under 600 Claude conversations before removing them, and Anthropic said then it had blocked crawlers.

OpenAI walked into it too. Last year 404 Media found nearly 100,000 shared ChatGPT conversations searchable on Google, and OpenAI pulled the feature. Elon Musk’s Grok was caught the same way.

Anthropic has had a run of data-exposure stories this year. Researchers showed Claude Cowork could break out of its sandbox and read credentials on a Mac. Grok Build was found up whole code repositories. Those were bugs. This was the product working correctly.

What to actually do #

Anthropic appears to have addressed the indexing. As of Monday afternoon the search technique returned nothing. Anyone already holding an old link can still reach it, though, and content can linger in caches and third-party archives.

Users can review what they have shared under Settings, then Privacy, then Shared Chats, and revoke any link there.

The wider lesson sits above any one setting. Chatbots now absorb the role of confidant for work, health and legal worries, so the share button carries far more than a link. Anthropic’s own tightening privacy regime shows it knows the stakes.

Tools like credential systems that never expose the underlying data show what careful handling looks like. A feature that quietly publishes a medical file is the opposite, and calling it intended does not make it safe. The pattern of AI security failures this year keeps pointing at one root: systems that treat access as consent.

Get the TNW newsletter #

Get the most important tech news in your inbox each week.

── more in #ai-products 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-says-your-…] indexed:0 read:4min 2026-07-28 ·