Anthropic claims that the leaked Claude conversations functioned as expected.
Enter the correct search query into Google over the weekend, and you could view conversations between users and Claude. Some of these included medical records, company files, and children’s phone numbers. The discussions were not technically hacked or leaked; they were shared by users through a Claude feature designed for this purpose. Subsequently, search engines indexed these pages just like any other public link. Anthropic asserts that nothing went wrong; they claim the system is functioning as expected.
How it came to light
On Saturday, a Reddit user brought it to attention. Using the search operator “site:claude.ai/share” revealed a lengthy list of shared Claude chats. 404 Media reported on it Monday, with other tech media outlets following quickly after. By default, Claude conversations are private; only those shared were affected. Sharing creates a snapshot of the conversation with its own public web address, intended for a colleague or a small group. The issue lay in the interpretation of “public.” A simple “noindex” tag tells search engines to exclude a page from results, and it appears Anthropic did not implement one.
What was revealed
The disclosed information was significant. Futurism examined the findings via Google and discovered detailed medical reports on identifiable patients, clinical trial results naming patients, and documents containing the names and phone numbers of children in primary school. Other instances were troubling for being ordinary; for example, Reddit users mentioned someone developing a crypto wallet who mistakenly exposed its keys, and another individual who asked Claude whether they needed to report a breach of professional conduct. Claude Artifacts, which are the interactive applications and documents users create with the tool, were also included. Internal dashboards and project plans containing client data were found alongside the chats.
Anthropic's response
When asked what occurred, Anthropic did not propose a solution but elaborated on the design. According to spokesperson Amie Rotherham, “We give people control over sharing their Claude conversations publicly, and in alignment with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links cannot be guessed or discovered unless individuals choose to share them themselves. By sharing a conversation, they are making that content publicly available.” The company noted that links appear in search results only after a user posts them somewhere accessible to crawlers, effectively shifting the responsibility to the users who clicked share.
The unfavorable comparison
This argument encounters a clear counterexample: Google Docs, which has a similar sharing feature, does not make its documents searchable on Google. The key difference is the absence of an instruction for search engines. Google spokesperson Ned Adriance indicated that site owners maintain control over crawling and indexing, and that Google honors these settings. The decision not to implement them was Anthropic's.
Underlying this is a disparity in the definitions of consent. While Anthropic is correct that sharing makes content public, it raises the concern of whether the individual sharing a patient file truly understood they were exposing it to the open internet.
This issue is not unprecedented
This isn't a new situation, which is what makes it noteworthy. Forbes reported nearly the same incident last September, when Google indexed about 600 Claude conversations before removing them. At that time, Anthropic claimed it had blocked crawlers. OpenAI also encountered similar problems; in 2022, 404 Media found nearly 100,000 shared ChatGPT conversations searchable on Google, prompting OpenAI to disable that feature. Even Elon Musk’s Grok faced the same predicament.
Anthropic has faced several data exposure issues this year. Researchers demonstrated that Claude Cowork could escape its sandbox and access credentials on a Mac, while Grok Build was found to upload entire code repositories. Those were bugs, but this instance was a case of the product functioning as designed.
What should be done
It seems Anthropic has addressed the indexing issue, as searches returned nothing by Monday afternoon. However, anyone with an old link can still access it, and content may persist in caches and third-party archives. Users can check what they have shared under Settings, then Privacy, and then Shared Chats, and revoke any links there.
The broader lesson transcends any individual setting. Chatbots now serve as confidants for work, health, and legal issues, so the share button carries much more weight than just a link. Anthropic's own tightening privacy measures indicate it understands the stakes involved. Tools like credential systems that never expose the underlying data exemplify careful management. A feature that surreptitiously publishes a medical file demonstrates the opposite, and simply labeling it as intended does not ensure safety. The series of AI security failures this year points to a common issue: systems treating access as a form of consent.
Other articles
Anthropic claims that the leaked Claude conversations functioned as expected.
Claude chats that were shared, including medical documents and children's phone numbers, could be found through Google searches. Anthropic asserts that the feature functioned as designed.
