Anthropic’s Claude chatbot exposed private chats, including medical details and cryptocurrency wallet information, to Google and Bing search for the second time in ten months. Reddit users found the leak over the weekend using a single search command, and both engines had scrubbed the results by Tuesday morning.
The same failure has hit two other major platforms recently. Google Drive documents shared with what users thought was a small audience have turned up in search results too, some dating back to 2003, and OpenAI’s ChatGPT suffered a nearly identical exposure the month before Anthropic’s own first leak.
A Search Command Exposed Anthropic’s Blind Spot
The exposure came to light after Reddit users found that typing “site:claude.ai/share” into Google or Bing pulled up a long list of Claude conversation logs, some containing deeply personal material. Once a Claude user creates a public link to a chat, anyone holding that link can view the full conversation, a setup similar to the “anyone with the link” option on Google Docs.
What caught users off guard was that the links did not stay confined to whoever they were sent to. Wired, which reviewed several of the exposed pages before they came down, found threads containing medical details, unreleased business plans and cryptocurrency wallet seed phrases. Other outlets that reviewed the pages, including IBTimes, reported chat logs containing API keys and children’s personal information.
The cause traced back to a missing safeguard. Search engines tell developers to add a “noindex” HTML tag to any page that should never appear in results, which stops crawlers from listing it at all. Many of the exposed Claude pages did not carry that tag, Wired found. Anthropic has said it relies on a robots.txt file, separate instructions that tell crawlers what they may log, but that does not guarantee removal the same way a tag that drops a page from Google’s results entirely does.
What we know:
- Google and Bing had scrubbed the exposed Claude pages by Tuesday morning.
- The exposed pages lacked a noindex tag, according to Wired’s review.
- Anthropic had a nearly identical leak in September 2025.
What’s unconfirmed:
- How many Claude conversations were indexed in this latest round.
- Whether Anthropic has since added noindex tags to shared pages.
- How long some exposed Google Drive files, including ones dating to 2003, had actually been searchable.
Anthropic’s Second Time in Ten Months
This was not Anthropic’s first time. Forbes reported a nearly identical exposure at the company in September 2025, when Google had indexed just under 600 Claude conversations. Anthropic told Forbes then that the chats became visible because users had shared the links elsewhere online or on social media, and said its robots.txt file was meant to prevent exactly that.
OpenAI ran into a larger version of the same problem the month before, in August 2025. ChatGPT let users tick a box marked “Make this chat discoverable” when generating a share link, and many either missed the warning or misread what it meant. Google ended up indexing roughly 100,000 shared ChatGPT conversations containing personal details, health questions and professional material, according to 404 Media.
OpenAI’s chief information security officer, Dane Stuckey, pulled the discoverability option within days. “Ultimately, we think this feature introduced too many opportunities for folks to accidentally share things they didn’t intend to, so we’re removing the option,” he wrote on X, calling it a “short-lived experiment.”
| Incident | When | Scale | Root Cause |
|---|---|---|---|
| OpenAI, ChatGPT | August 2025 | ~100,000 conversations indexed (404 Media) | Opt-in “discoverable” checkbox users misread |
| Anthropic, Claude | September 2025 | Just under 600 conversations (Google estimate via Forbes) | Missing noindex tag on shared pages |
| Anthropic, Claude | July 2026 | Not officially disclosed | Same missing noindex tag, per Wired |
Anthropic has now accounted for two of the three known incidents, both traced to the same missing tag.
Google Drive’s Exposure Goes Back to 2003
Claude was not the only place the Guardian went looking. Using a similar search technique on Google Drive, its reporters found a long list of public documents users likely never meant to publish this widely.
- Exams from specific elementary and high schools, turned up by searching Drive files containing the word “test”
- Results of lead and radon detector tests tied to specific home addresses
- A city health department’s confidentiality agreement, meant for internal use, found by searching for the word “confidential”
- Files whose sharing settings had gone unchanged since as far back as 2003
Ross Richendrfer, a Google spokesperson, said the documents were discoverable because the links had been posted somewhere on the internet or social media at some point, not because Google actively sought out private files.
Why Does “Anyone With the Link” Keep Failing?
Neither Google nor Anthropic warns users at the moment they create a shareable link that the page could later show up in search results. Once a link leaves its original small audience through a forward, a screenshot or a social post, the platform loses control of who sees it, and crawlers can eventually find it.
That gap between what users assume and what the technology actually guarantees is what worries privacy advocates most.
The privacy afforded by ‘anyone with a link’-style sharing of chats and documents is fragile. If you share something with a friend, and they share it with a friend, and they post it to social media, suddenly it’s findable and readable by anyone on the web.
Jacob Hoffman-Andrews, a senior staff technologist at the Electronic Frontier Foundation (EFF), a digital rights advocacy group, recommended “extreme caution” before creating any shareable link, suggesting alternatives such as copying and pasting text or taking a screenshot instead.
Anthropic has defended its design in similar terms, saying the sharing feature is working as intended and that shareable links “are not guessable or discoverable unless people choose to share them themselves.” That echoes what Google’s Richendrfer said about the exposed Drive files: the fault sits with users who shared a link too widely, not with the platform’s defaults.
Designing products this way is deliberate, Hoffman-Andrews added. “Designing to incentivize viral sharing can also lead to users unintentionally oversharing,” he said.
Locking Down a Claude Chat or a Google File
Both companies let users undo a public link after the fact, though neither guarantees instant removal from a search engine’s existing index.
On Claude’s desktop browser:
- Click the profile icon in the bottom-left corner and choose Settings.
- Open the Privacy tab and scroll to the Your Data section.
- Click Manage next to shared chats to see every conversation made public.
- Select a chat and switch it from Public to Private, or delete the thread outright.
Anthropic’s own privacy documentation confirms the same steps, explaining how to switch a shared conversation from public back to private, and notes that anyone on a free, Pro or Max plan can review the list.
Google Drive works differently, and less conveniently. There is no single dashboard listing every file a user has made public; each document has to be opened on its own. Click Share in the top right corner, then change General Access from Anyone with the link to Restricted, or to specific people, groups or spaces.
Frequently Asked Questions
Does Making a Claude Chat Private Remove It From Google Immediately?
Not necessarily. Switching a chat from Public to Private stops anyone new from opening the link, but a version Google or Bing already indexed can linger in results until the engine recrawls the page and notices it is gone. Treat anything ever shared as potentially public for a while longer.
Do Shared Claude Chats Include Uploaded Files or Images?
No. Anthropic’s privacy documentation states that if a shared conversation had an attached file, the file itself is excluded from the public snapshot. Only the visible conversation text and Claude’s responses become part of the shared page.
Is This Only a Problem for AI Chatbots and Google Drive?
No. Security researchers have documented the same failure mode on other platforms for more than a decade. “Secret” GitHub gists and raw code files have turned up in Google searches years after being made private, often exposing API keys and passwords along the way.
Why Did Bing Take Longer Than Google to Clear the Results?
Search engines recrawl and refresh their indexes on different schedules. Coverage of the incident found Google had scrubbed the exposed Claude links faster, while Bing continued surfacing some pages for longer before both were clear by Tuesday morning.
What Should I Do if I Already Shared Something Sensitive?
Treat the link as compromised. Delete or unpublish it using the steps above, then assume the underlying information may already have been copied, cached or screenshotted elsewhere rather than trusting that one settings change erases it everywhere.








