cd /news/ai-safety/claude-shared-chats-have-been-indexe… · home topics ai-safety article
[ARTICLE · art-74200] src=startupfortune.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Claude shared chats have been indexed by Google and anyone with a search bar can find them

Roughly 600 Claude conversations surfaced in Google search results before Anthropic moved to remove them, and more than 143,000 AI chatbot chats across Claude, Copilot, and ChatGPT are sitting in public view on Archive.org, according to research from Obsidian Security. Anthropic told Forbes it intends to block crawlers from indexing shared chats, but the exposure has already led to live credentials, confidential salary data, and internal VC memos being discoverable via simple search queries. Separately, attackers have been exploiting Claude's shared-chat URL format in a malvertising campaign since May 2026, with Zscaler tracking 22 unique Google Ads campaign IDs that pushed users toward fake installation guides, resulting in more than 15,600 confirmed victims of the MacSync infostealer.

read4 min views1 publishedJul 26, 2026
Claude shared chats have been indexed by Google and anyone with a search bar can find them
Image: Startupfortune (auto-discovered)

Roughly 600 Claude conversations surfaced in Google search results before Anthropic moved to remove them, and more than 143,000 AI chatbot chats across Claude, Copilot, and ChatGPT are sitting in public view on Archive.org, according to research from Obsidian Security.

If you've ever pasted a cap table, an AWS key, or a draft investor memo into Claude and hit share, there's a real chance that conversation is no longer private. Not because Anthropic was hacked. Because of a feature working exactly as designed, landing in places it wasn't supposed to. Claude's share function generates a public URL for a conversation transcript. The idea is simple enough: you want to show a colleague what you've been working on. But those URLs, once created, can get picked up by crawlers, land in Slack exports or forum threads, and end up on Archive.org or in Google's index. Anthropic told Forbes it intends to block crawlers from indexing shared chats, but the approximately 600 conversations Google had indexed before they were removed suggest that intent and execution aren't the same thing. Obsidian Security's broader sweep found AWS Access Key IDs, API tokens, and other live credentials sitting in those 143,000 archived chats across AI platforms.

The types of material showing up in searches are exactly what you'd expect from the way founders and investors actually use these tools. Confidential salary data, internal VC investment memos, court filings, and authentication credentials have all surfaced through straightforward search queries. Researchers used phrases as simple as "site:claude.ai internal use only" to pull them up. These aren't exotic attack techniques. Anyone who knows to try it can find this material.

The exposure isn't limited to accidental indexing. Since at least May 2026, attackers have been weaponizing Claude's shared-chat URL format in a separate but related threat. Zscaler traced an active malvertising campaign from June 12 to June 19 that used 22 unique Google Ads campaign IDs to push users toward Claude.ai shared chats disguised as official installation guides. Those chats instructed visitors to paste Terminal commands that installed MacSync, a macOS infostealer targeting browser credentials, Keychain data, and crypto wallets. Cybersecurity News reported more than 15,600 confirmed victims, with 67% of traffic concentrated in the Asia-Pacific region. Claude itself wasn't compromised; the attackers simply exploited the fact that a claude.ai URL looks trustworthy.

Anthropic updated its privacy policy effective July 8, 2026, adding identity verification requirements for some consumer-tier users, including government-issued ID and facial biometrics for flagged accounts. The update also introduced new rules governing how data flows when Claude executes multi-step agentic tasks through third-party app integrations. Those are real changes. But they don't directly address the shared-chat indexing problem, and they don't apply to Team, Enterprise, or Platform users at all.

What you should do right now #

Frankly, the practical risk here is straightforward to state even if Anthropic hasn't made it easy to act on. Any conversation you shared in the past may still be sitting on Archive.org regardless of whether Google has since deindexed it. The fix Anthropic can offer, removing content from its own servers, doesn't reach archive copies. That's not a criticism unique to Claude; the same applies to the exposed ChatGPT and Copilot conversations in Obsidian Security's dataset. But it does mean the corrective action has to start with you.

Go through your shared-chat history and revoke any links to conversations that contain credentials, financials, or anything you'd consider non-public information. Don't share anything you wouldn't post to a public Slack channel. If you're using Claude for legal work, note that federal prosecutors argued in February 2026 that documents created through Claude queries may not qualify for attorney-client privilege. That case hasn't set binding precedent, but it signals the direction courts are heading on AI-assisted legal drafting.

The deeper issue is that the share feature was built with convenience as the primary design goal. That's not a bad instinct. It's how most collaboration tools are built. But when those tools are being used to process cap tables, salary data, and authentication tokens, the default settings have to account for the realistic ways shared links behave in the wild, not just the intended use case. Until Anthropic tightens that, the safest assumption is that any conversation you mark as shared is, eventually, public.

Also read: Georgia Power is seizing family homes to build AI data center power lines and residents are calling it theftSingapore's Ropedia raises $30M to teach robots how to do chores by watching humansChinese AI models are taking US market share and the price gap explains everything

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/claude-shared-chats-…] indexed:0 read:4min 2026-07-26 ·