Security firm reveals Claude shared conversations can...

Claude shared chats and Artifacts could be indexed by Google, exposing sensitive user and company information through public search results.

Incident Overview

Security firm Malwarebytes reported that conversation shares created through Anthropic’s Claude Share chats feature could be found by Google Search, causing content that was originally intended only for specific recipients to unexpectedly appear in public search results.[1][2] The issue was first discovered by Reddit users, who were able to use a specific search query to find large numbers of Claude share pages on Google.[2][3]

According to public reports, the indexed content included résumés, health conditions, internal company data, and even API keys and other sensitive information.[1][2] Source summaries also note that Anthropic’s documentation indicates that Share chats changes a conversation’s status to Public and creates a share link that others can access.[1]

It is worth noting that this is not an issue unique to Claude. Malwarebytes previously found Grok conversation records in Google search results, and Meta AI has experienced similar incidents, showing that this kind of risk is a common exposure problem for generative AI platforms.[1]

Technical Analysis

The core of this incident is not a traditional intrusion or database breach, but a mismatch between public share links and search engine indexing.[1][3][5] Once a user actively creates a shared page, the system generates a publicly readable URL; if that page is indexed by a search engine, it may appear in search results.[3][5]

From a risk-modeling perspective, the danger of this kind of event is that it changes the visibility boundary of information. Content originally designed to be viewed by “anyone with the link” becomes keyword-searchable, cross-platform, and potentially persistent public information once a search engine indexes it.[2][5][8] For users, this means that “shared” does not necessarily mean “shared with only a few people,” because search engines and reposting platforms can expand the audience far beyond what was expected.[3][10]

In addition, reports note that Claude’s public Artifacts may also be searchable, including interactive mini-apps and documents.[3][7][8] This means the problem is not limited to plain text chats, but may also extend to documents, dashboards, workflow prototypes, and other data types with greater business value.[8][15]

Scope of Impact

The primary affected group is users who used Claude’s sharing feature and entered sensitive information into their conversations.[2][12][15] The exposed content cited in reports included résumés, health conditions, internal company data, and API keys, showing that the impact is not limited to personal privacy and may also involve corporate confidentiality and legal risk.[1][2][8][12]

For individual users, the most direct consequences are privacy leakage and identity risk; for enterprise users, if employees entered internal documents, customer data, unpublished product plans, or internal discussions into Claude and shared them, this could create data leakage, contract breach, and governance liability issues.[8][10][11][15] Some reports even say that public samples included employee salary sheets, internal CRM records, and unreleased product roadmaps, indicating that the impact could directly affect operational and competitive information.[3]

From an attack-surface perspective, this kind of exposure does not require exploiting a vulnerability, privilege escalation, or malware; anyone who knows the search syntax can find a large amount of content.[3][6][12] This also means the risk threshold is very low, and any third party may obtain information that should not have been public through simple search, then screenshot it, archive it, or redistribute it again.[6][7][14]

Protection Recommendations

For ordinary users, the most important principle is: do not put sensitive information directly into AI conversations, especially national ID numbers, keys, passwords, medical information, financial information, or internal company data into any feature that can generate share links.[2][12][15] Malwarebytes also explicitly recommends that if you do not want information to spread publicly, the simplest step is not to share AI conversation content with anyone, or to avoid sharing personally identifiable information.[1]

For enterprises, generative AI should be included in data classification and exfiltration control policies, with a clear prohibition against placing confidential data, customer data, and regulated information into external AI platforms.[8][10][11] At the same time, security and compliance teams should establish audit procedures to periodically check whether employees have created public share pages or entered sensitive information into conversations, and incorporate AI platform usage rules into training and incident response procedures.[11][12][15]

From a platform-design perspective, this incident also reminds developers that share-visibility controls must be treated as a default security baseline, not an optional add-on.[3][5] Publicly shareable pages should also be evaluated for access authentication, share expiration, and revocation mechanisms to prevent “shareable” from being misunderstood as “searchable by the public.”[5][10]

5-Step Fix Checklist

  • Immediately check Claude’s Shared Chats and Shared artifacts, and delete all unnecessary public links.[14][15]
  • Review whether any keys, API keys, passwords, personal data, medical content, or legal content were ever entered into AI conversations, and update related credentials and data as needed.[2][5][12]
  • Do not paste confidential documents, internal notes, customer data, or unpublished plans into shareable AI tools.[8][10][11]
  • Establish an AI usage policy inside the company that clearly defines what data may and may not be used, and include it in employee training.[11][15]
  • Regularly self-audit public exposure using search queries, confirm whether related content is still being indexed by search engines, and continue monitoring platform remediation status.[3][6][14]

References

  • ITNEWS ISC: Security firm reveals Claude shared conversations can be found on Google, potentially exposing users’ sensitive information
  • Malwarebytes: Shared Claude chats were searchable on Google
  • Business Next: Claude sharing feature sparks privacy concerns! One search query can uncover private content on Google
  • PANews: Anthropic configuration error caused Claude shared conversations to become publicly searchable, leading to user privacy leaks
  • TechCrunch: PSA: Your Claude shared chats and Artifacts may have ended up on Google
  • New MobileLife: Netizens found Claude chat logs exposed in Google search results
  • TechNews Security: Claude suffers major privacy leak, Google search reveals “chat records and crypto private keys”
  • KOCPC: Shared content fully indexed by Google, exposing API keys and private information
  • Business Next: Claude share links can be found on Google! Self-check company secrets for leaks with one search query, and close public access in 4 steps
  • ETtoday: Claude hits major privacy scandal! Chat logs can actually be searched on Google

More cybersecurity news