Anthropic stated that the leaked Claude conversations functioned as expected.
If you entered the correct query into Google over the weekend, you could access conversations with Claude shared by strangers. Some discussions included medical records, business documents, and the phone numbers of children. These chats were neither hacked nor technically leaked; users intentionally shared them using a feature designed for that purpose, leading search engines to index these pages like any other public link. Anthropic maintains that the system functioned as it was supposed to.
The incident came to light when a Reddit user reported it on Saturday, using the search operator “site:claude.ai/share,” which displayed numerous shared Claude chats. 404 Media was the first to publish a report on it Monday, followed by rapid coverage by other tech outlets. Conversations on Claude are private by default, but only those that were shared were implicated. When a conversation is shared, it creates a snapshot accessible at a public web address intended for a colleague or a small audience. The issue arose from the meaning of "public." A straightforward “noindex” tag instructs search engines to omit a page from results, and it appears that Anthropic did not implement one.
The content that was exposed was significant. Futurism examined the findings via Google and discovered a detailed medical report for a specific patient, clinical-trial outcomes naming patients, and documents listing the names and phone numbers of children in primary school. Some cases were particularly troubling due to their ordinary nature, such as a user disclosing cryptocurrency wallet keys and another being a lawyer inquiring about self-reporting a professional conduct breach.
Claude Artifacts, which are interactive applications and documents created within the tool, were also part of this exposure, revealing internal dashboards and project plans containing client information alongside the chats.
When asked about the incident, Anthropic did not provide details on a fix but discussed the design. Amie Rotherham, a spokesperson for the company, stated, “We allow users to control the public sharing of their Claude conversations, and in line with our privacy principles, we do not share chat directories or sitemaps with search engines like Google.” She further mentioned that these sharable links are not guessable or discoverable unless users opt to share them. Once shared, the content becomes publicly accessible.
The company asserted that links only appear in search results when a user posts them in a place visible to crawlers, thereby placing the onus on those who chose to share.
This defense, however, faces a clear counterexample. Google Docs has a similar sharing feature, yet those documents do not show up in Google searches. The difference lies in the absence of instructions to search engines; Google’s spokesperson Ned Adriance noted that website owners control crawl and index permissions, which Anthropic chose not to exercise.
This incident highlights a discrepancy between two definitions of consent. While Anthropic is technically accurate that sharing makes content public, the more challenging question remains whether individuals sharing sensitive patient information realized it was being published on the open web.
This issue is not unprecedented, which is what makes it notable. Last September, Forbes reported a similar situation where Google indexed nearly 600 Claude conversations before they were removed. Anthropic previously stated that it had blocked crawlers. OpenAI faced a similar predicament when 404 Media discovered nearly 100,000 shared ChatGPT conversations that were searchable on Google, prompting OpenAI to eliminate the feature. Elon Musk’s Grok encountered a similar issue.
Anthropic has seen a series of data exposure incidents this year, with researchers demonstrating that Claude Cowork could escape its sandbox and access credentials on a Mac, and Grok Build was found uploading entire code repositories. Those instances were bugs, while this incident was the product functioning as designed.
As of Monday afternoon, Anthropic appears to have resolved the indexing issue; the search method no longer returned results. Nevertheless, individuals who possess old links can still access them, and content may persist in caches and third-party archives. Users can review what they have shared by navigating to Settings, then Privacy, and subsequently Shared Chats, where they can revoke any links.
The broader lesson extends beyond any specific feature. Chatbots are increasingly being relied on as confidants for work, health, and legal concerns, meaning the share button has much greater implications than merely providing a link. Anthropic’s own tightening of privacy measures indicates an awareness of the potential consequences. Tools that incorporate credential systems without revealing underlying data exemplify careful management. A feature that quietly shares a medical file exemplifies the opposite, and labeling it as intended does not ensure safety. The ongoing pattern of AI security breaches this year continues to highlight a common root issue: systems that equate access with consent.
Other articles
Anthropic stated that the leaked Claude conversations functioned as expected.
Claude chat conversations, which included medical documents and children's phone numbers, were accessible through Google searches. Anthropic claims that the feature functioned as it was designed to.
