- The verified exposure involved user-created public snapshots, not private Claude chats or a breach of Anthropic’s accounts. [1] - Claude share links were indexed as early as September 2025, when Google estimated that it had listed just under 600 conversations; claims of thousands in the latest episode remain unverified. [2] - Google results disappeared by July 26, but removing a search listing does not disable the underlying public link.
[3] Publicly shared Claude conversations resurfaced in search results over the weekend, making user-published chat snapshots easier to discover through Google, Bing and Brave Search. Reports described credentials, personal information and confidential work material among the results, although MLQ did not access or reproduce sensitive conversations. The verified exposure concerns chats whose users had activated Claude’s sharing feature, which creates a snapshot accessible to anyone holding its URL. [1]
This is a recurrence rather than a new breach. Google estimated that it had indexed just under 600 Claude conversations in September 2025. Anthropic spokesperson Gabby Curtis said then that the company did not provide search engines with directories or sitemaps and actively blocked crawlers; the pages appeared because their links had been posted elsewhere online. [2]
The latest discovery spread on July 25, 2026. Google results disappeared within hours, while researchers reported that some listings remained on Bing and Brave longer. No reliable count of affected pages or users has emerged, and Anthropic had not issued a fresh public explanation by July 27. [3]
A crawler configuration left links discoverable #
Archived copies show Anthropic added a robots.txt rule blocking crawlers from /share/* on August 2, 2025. Share pages also returned an X-Robots-Tag: none instruction, equivalent to noindex, nofollow. Google warns that this combination can fail: when robots.txt prevents its crawler from opening a page, the crawler cannot read the noindex header, and externally linked URLs may still appear in results. [3][4]
Anthropic’s current help documentation still offers public sharing, and no confirmed product change beyond the disappearance of Google listings was evident Monday. Users should open Settings, select Privacy, manage Shared chats and unshare anything unnecessary. [1]
If a shared chat contained a password, API token, database credential or private key, deleting the link is insufficient. Revoke the exposed credential at its provider, generate a replacement, update affected systems and review access and billing logs. Anthropic warns that stolen API keys can produce unauthorized charges, while OWASP recommends immediate revocation and rotation for any potentially compromised secret. A disclosed cryptocurrency seed phrase or private key should be treated as permanently compromised, with assets moved to a newly generated wallet. [5][6]
Companies mentioned #
Further sources #
[1] Anthropic, “Share and unshare chats,” June 15, 2026. ↗ [2] Forbes, “Hundreds Of Anthropic Chatbot Transcripts Showed Up In Google Search,”… ↗
[[3] Daniel J. Glover, “Shared Claude conversations hit Google,” July 26, 2026. ↗](https://danieljamesglover.com/blog/2026-07-26-shared-claude-conversations-google/)
[[4] Google Search Central, “Block Search indexing with noindex.” ↗](https://developers.google.com/search/docs/crawling-indexing/block-indexing)
[[5] Anthropic, “API Key Best Practices: Keeping Your Keys Safe and Secure,” March 1… ↗](https://support.claude.com/en/articles/9767949-api-key-best-practices-keeping-your-keys-safe-and-secure)
[[6] OWASP Cheat Sheet Series, “Secrets Management.” ↗](https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html)
The stories that matter, in one email. Free — unsubscribe anytime.