Your Private Claude Chats May Have Been Sitting in Google Search Results All Weekend

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Exposure method: Reddit users found that typing "site:claude.ai/share" into Google surfaced shared Claude conversations and artifacts.
  • Sensitive data: Exposed content reportedly included health records, private company documents, and children’s data.
  • Apparent fix: By Monday afternoon, a test search returned no results, suggesting the issue had been remediated.

Shared Claude chats and Artifacts became publicly searchable on Google over the weekend, exposing an untold number of user conversations. The exposure traces back to Claude's "share chat" feature, which generates links letting anyone holding the URL view a conversation or project

How the Claude Chats Surfaced on Google

Claude's own interface warns "anyone with the link can view," language that clearly points toward sharing with friends, colleagues, or small groups, not the open internet. Reddit users discovered that entering "site:claude.ai/share" into Google returned a long list of shared Claude conversations – no direct link required, no invitation needed. 

According to Futurism, the exposed material reportedly included:

Reddit user reports that a simple Google dork request retrieves Claude shared conversations via Google | Source: Reddit
Reddit user reports that a simple Google dork request retrieves Claude shared conversations via Google | Source: Reddit

Timeline and Prior Incident

404 Media reported the incident on Monday after Reddit users posted about this on Saturday. By Monday afternoon, a TechCrunch test search following the same method returned no results, possibly signaling the exposure had been fixed, even without a detailed technical explanation from Anthropic

Anthropic has not published a technical description of the fix, confirmed its effective date, or estimated how many conversations were indexed before Monday. Nor has the company clarified yet how many were indexed in total, whether any were specifically targeted, how long the window was open, or whether similar gaps exist elsewhere.

This isn't the first time it's happened, either: a similar incident occurred in 2025, when Google estimated it had indexed just under 600 Claude conversations before the pages disappeared from search results. This type of exposure was linked in the past to other AI agents as well, as Grok exposed chats and OpenAI ChatGPT exposed user chats via the 'Make Link Discoverable setting.

Anthropic and Google Respond

Anthropic spokeswoman Amie Rotherham said the share links "are not guessable or discoverable unless people choose to share them themselves," adding that once someone shares a conversation, that content becomes publicly accessible and may end up archived by third-party services. 

Google spokesperson Ned Adriance pushed back on the idea that Google was at fault, saying neither Google nor any other search engine controls what pages get made public on the web, and noting that Google gives site owners clear controls over crawling and indexing.

A Kaspersky report earlier this month warned that Claude Code captured confidential files last year. In May, cybersecurity researchers observed attackers abused Google Ads and Claude.ai shared chats to distribute Mac malware.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: