cd /news/ai-safety/claude-chats-ended-up-on-google-sear… · home topics ai-safety article
[ARTICLE · art-76904] src=firethering.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Claude Chats Ended Up on Google Search. Here’s How It Happened.

A Google search operator revealed hundreds of shared Claude conversations indexed on Google, exposing sensitive data including medical records, children's personal information, and internal company documents. The issue stems from Anthropic's share feature generating public links that search engines can crawl, and this is not the first such incident — a similar exposure occurred in 2025. Anthropic has not yet commented on the latest leak.

read5 min views1 publishedJul 28, 2026
Claude Chats Ended Up on Google Search. Here’s How It Happened.
Image: Firethering (auto-discovered)

A single line typed into Google was all it took. Type “site:claude.ai/share” into the search bar, and over the weekend, it surfaced a long list of conversations people had shared through Claude, Anthropic’s AI chatbot. Not conversations they’d shared with the world on purpose. Conversations they’d shared with one person, or thought they had.Some of what turned up reads like exactly the kind of thing you’d never want indexed anywhere. Medical records. Children’s names and phone numbers. Internal company documents marked for employees only. This wasn’t a hack, no one broke into anything. It was a feature working exactly as built, surfacing exactly what people had typed into it, in ways most of them almost certainly never intended.

Table of Contents

How it was discovered

Claude has a share feature that lets users generate a link to a conversation or an Artifact, the interactive documents and mini apps you can build inside a chat, so it can be sent to someone else. The interface itself warns “anyone with the link can view,” language that reads like it’s built for sending a link to a colleague or a friend, not for publishing to the open internet.

That’s the gap. A link built to be shared quietly can still end up somewhere a search engine can crawl it, whether that’s a forum post, a social media share, or some other public corner of the web where the link got dropped. Once a search engine finds it, it can get indexed like any other public page, and from there, it’s one search query away from anyone who knows to look.

Google’s Docs sharing feature works differently. Documents shared privately there don’t end up crawlable the same way. That’s part of why this particular gap surprised people. Users are used to “share with a link” meaning something closer to private, not “publicly searchable if the wrong person reposts it.”

What was actually sitting in those chats

Before the exposure got cleaned up, reporters combing through the indexed pages found a detailed medical report belonging to a real patient. Clinical trial data with patient names attached. Documents listing the names and phone numbers of primary-school-aged children. Internal company files marked for employee eyes only, alongside performance reviews containing personal information about the people being reviewed.

At least one exposed conversation, labeled as shared by Anthropic itself, reportedly showed Claude generating erotica, output that runs directly against Anthropic’s own usage policy, which explicitly prohibits sexually explicit content. How that particular output got produced isn’t clear from the exposed chat alone. Getting a chatbot to break its own content rules through persistent or creatively worded prompting is a pattern that shows up periodically across pretty much every major AI assistant, not something unique to Claude.

None of this required sophisticated snooping. It required knowing one search operator and having a few minutes to scroll.

Also Read: OpenAI Says Its AI Escaped Testing and Hacked Hugging Face This isn’t the first time

If this feels familiar, that’s because it is. Last year, Forbes reported a nearly identical issue: hundreds of Claude conversations turned up indexed by search engines, with Google alone estimated to have caught just under 600 of them before the pages disappeared from results. Whether this weekend’s exposure matches that scale isn’t independently confirmed, but multiple users reported finding shared chats using the exact same search technique that surfaced last year’s cache, which suggests the underlying gap was never fully closed. Claude isn’t the only assistant this has happened to either. Also last year, 404 Media reported that a researcher managed to scrape roughly 100,000 ChatGPT conversations that users had set to share publicly. Different company, same basic failure mode: a share feature built for small, deliberate sharing that turns into something searchable by anyone the moment it touches the wrong corner of the public web.

That repetition is the real story here. This isn’t a one-off bug. It’s a structural risk built into how “shareable link” features work across the industry, one that keeps resurfacing because the underlying design keeps getting reused.

How to check and protect your shared chats

If you’ve ever used Claude’s share feature, even once, it’s worth checking what’s actually out there under your account. Go to Settings, then Privacy, then Shared Chats. That section shows every conversation you’ve set to have a public link. Go through it and pull the shared status from anything containing personal details, passwords, financial information, confidential work material, or sensitive business plans, basically anything you wouldn’t want a stranger to stumble across through a Google search.

Going forward, treat the share link the way you’d treat posting something publicly, not the way you’d treat a private message. If you post that link anywhere public, a forum, a group chat that gets screenshotted, a social media post, there’s a real chance it gets crawled and indexed eventually. Before you share a conversation again, take the extra few seconds to reread it for anything sensitive first.

**Wrap Up **

Nobody broke into Claude’s servers. Every one of those exposed conversations went out through a feature working exactly as designed, one click at a time, by people who mostly had no idea where that click would eventually lead.

That’s the uncomfortable part. The failure wasn’t technical. It was a gap between what a “share” button implies and what it actually does, and that gap is wide enough to swallow a medical record, a child’s phone number, or a company’s internal files without anyone noticing until it’s already indexed.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/claude-chats-ended-u…] indexed:0 read:5min 2026-07-28 ·