back to top
HomeTechClaude Chats Ended Up on Google Search. Here's How It Happened.

Claude Chats Ended Up on Google Search. Here’s How It Happened.

- Advertisement -

A single line typed into Google was all it took. Type “site:claude.ai/share” into the search bar, and over the weekend, it surfaced a long list of conversations people had shared through Claude, Anthropic’s AI chatbot. Not conversations they’d shared with the world on purpose. Conversations they’d shared with one person, or thought they had.Some of what turned up reads like exactly the kind of thing you’d never want indexed anywhere. Medical records. Children’s names and phone numbers. Internal company documents marked for employees only. This wasn’t a hack, no one broke into anything. It was a feature working exactly as built, surfacing exactly what people had typed into it, in ways most of them almost certainly never intended.

How it was discovered

Claude has a share feature that lets users generate a link to a conversation or an Artifact, the interactive documents and mini apps you can build inside a chat, so it can be sent to someone else. The interface itself warns “anyone with the link can view,” language that reads like it’s built for sending a link to a colleague or a friend, not for publishing to the open internet.

That’s the gap. A link built to be shared quietly can still end up somewhere a search engine can crawl it, whether that’s a forum post, a social media share, or some other public corner of the web where the link got dropped. Once a search engine finds it, it can get indexed like any other public page, and from there, it’s one search query away from anyone who knows to look.

Google’s Docs sharing feature works differently. Documents shared privately there don’t end up crawlable the same way. That’s part of why this particular gap surprised people. Users are used to “share with a link” meaning something closer to private, not “publicly searchable if the wrong person reposts it.”

What was actually sitting in those chats

Before the exposure got cleaned up, reporters combing through the indexed pages found a detailed medical report belonging to a real patient. Clinical trial data with patient names attached. Documents listing the names and phone numbers of primary-school-aged children. Internal company files marked for employee eyes only, alongside performance reviews containing personal information about the people being reviewed.

At least one exposed conversation, labeled as shared by Anthropic itself, reportedly showed Claude generating erotica, output that runs directly against Anthropic’s own usage policy, which explicitly prohibits sexually explicit content. How that particular output got produced isn’t clear from the exposed chat alone. Getting a chatbot to break its own content rules through persistent or creatively worded prompting is a pattern that shows up periodically across pretty much every major AI assistant, not something unique to Claude.

None of this required sophisticated snooping. It required knowing one search operator and having a few minutes to scroll.

Also Read: OpenAI Says Its AI Escaped Testing and Hacked Hugging Face

This isn’t the first time

If this feels familiar, that’s because it is. Last year, Forbes reported a nearly identical issue: hundreds of Claude conversations turned up indexed by search engines, with Google alone estimated to have caught just under 600 of them before the pages disappeared from results. Whether this weekend’s exposure matches that scale isn’t independently confirmed, but multiple users reported finding shared chats using the exact same search technique that surfaced last year’s cache, which suggests the underlying gap was never fully closed.

Claude isn’t the only assistant this has happened to either. Also last year, 404 Media reported that a researcher managed to scrape roughly 100,000 ChatGPT conversations that users had set to share publicly. Different company, same basic failure mode: a share feature built for small, deliberate sharing that turns into something searchable by anyone the moment it touches the wrong corner of the public web.

That repetition is the real story here. This isn’t a one-off bug. It’s a structural risk built into how “shareable link” features work across the industry, one that keeps resurfacing because the underlying design keeps getting reused.

How to check and protect your shared chats

If you’ve ever used Claude’s share feature, even once, it’s worth checking what’s actually out there under your account.

Go to Settings, then Privacy, then Shared Chats. That section shows every conversation you’ve set to have a public link. Go through it and pull the shared status from anything containing personal details, passwords, financial information, confidential work material, or sensitive business plans, basically anything you wouldn’t want a stranger to stumble across through a Google search.

Going forward, treat the share link the way you’d treat posting something publicly, not the way you’d treat a private message. If you post that link anywhere public, a forum, a group chat that gets screenshotted, a social media post, there’s a real chance it gets crawled and indexed eventually. Before you share a conversation again, take the extra few seconds to reread it for anything sensitive first.

Wrap Up

Nobody broke into Claude’s servers. Every one of those exposed conversations went out through a feature working exactly as designed, one click at a time, by people who mostly had no idea where that click would eventually lead.

That’s the uncomfortable part. The failure wasn’t technical. It was a gap between what a “share” button implies and what it actually does, and that gap is wide enough to swallow a medical record, a child’s phone number, or a company’s internal files without anyone noticing until it’s already indexed.

Don’t miss any Tech Story

Subscribe To Firethering NewsLetter

You Can Unsubscribe Anytime! Read more in our privacy policy

LEAVE A REPLY

Please enter your comment!
Please enter your name here

YOU MAY ALSO LIKE

The Biggest AI Companies Are All Building Their Own Chips. That’s Not a Coincidence.

0
Anthropic confirmed this week it's hiring a custom silicon team to design chips for running Claude. The announcement was quiet a job listing, a spokesperson confirmation, no big launch event. Easy to file under "interesting but expected" and move on. But zoom out for a second. OpenAI shipped its first custom inference chip in June. Google has been running models on its own TPUs for years. Meta has designed and deployed its own silicon. Mistral is reportedly exploring the same path. And now Anthropic. Five of the most important AI labs in the world, all arriving at the same decision, within roughly the same window. None of them are copying each other. All of them looked at the same competitive landscape and reached the same conclusion independently. That kind of convergence doesn't happen by accident. It happens when an entire industry agrees that the thing everyone assumed was someone else's problem is actually the problem and that whoever solves it first has an advantage that's very hard to close later.
AI Was Supposed to Stop Cheating. Instead, 58,000 Students Must Retake Their Exams

AI Was Supposed to Stop Cheating. Instead, 58,000 Students Must Retake Their Exams.

0
UNAM runs the largest university in Mexico. Every year, hundreds of thousands of students take an entrance exam that determines whether they get in. This year, for the first time, the whole thing went remote. They deployed a lockdown browser, AI webcam monitoring, and one human supervisor per 150 applicants. The kind of setup that sounds serious on paper. Then the scores came in. Students hitting 100 or above jumped from 3.5 percent in previous years to 16.3 percent this year. At the very top end, scores of 110 or higher went from 0.9 percent to 5.5 percent. Not a small shift. Not noise. A roughly fivefold increase in top scores, in one year, under one new format. An expert commission investigated. Their conclusion: administer the entire exam again, in person, to around 58,000 people. The rector apologized to students who hadn't cheated. They now have to prepare for and sit another exam anyway.
Kimi K3 May Be the Biggest Open-Weight AI Release of 2026

Kimi K3 May Be the Biggest Open-Weight AI Release of 2026.

0
There's a new open-weight model out there right now that almost nobody can actually download. That should sound like a contradiction. Open-weight is supposed to mean anyone can grab the file and run it themselves, no waiting. Moonshot AI broke that pattern anyway, and the strange part is they broke it for a model big enough that the wait might be worth it. Kimi K3 is the largest open model ever built. The largest one anyone has shipped and early results have it beating Claude and GPT on tasks those two have spent the last year treating as their own territory. Open models have spent two years playing catch-up, closing gaps quarter by quarter while everyone waited for the day one of them actually pulled ahead. That day might already be here, and the model responsible for it is currently locked behind an app you can use but can't take home. So the question is what it actually beats, what it still can't touch, and why Moonshot decided to make the world wait for the weights while everyone else gets to watch.