top of page

Breaking: Claude chat logs exposed publicly on Google - Who is to blame?

Sharing AI conversations for teamwork or casual discussions with friends has become commonplace. However, a recent security incident involving Claude, Anthropic's AI assistant - has sent shockwaves through the tech community, as a vast amount of private user data was unexpectedly indexed and exposed publicly by Google Search.

An unexpected discovery from the tech community

The incident unfolded over the weekend when Reddit users discovered a concerning vulnerability. By using advanced Google search operators (specifically, site:claude.ai/share), they were able to pull up a long list of shared conversations and Artifacts - a term referring to the documents, code snippets, or interactive mini-apps that users build directly within Claude's workspace.

In reality, Claude offers a "share chat" feature designed to let users generate a URL to share with others. Although the app's interface displays a warning stating "Anyone with the link can view," most users implicitly understood this to mean sharing within a narrow circle, such as with friends or colleagues - similar to how Google Docs operates (which is not automatically indexed in public search results). The widespread appearance of these links on the public internet was clearly far from what users expected.

claude-share-chat
A screenshot of Claude's "Share chat" feature when the user selects the "Keep private" option

A wealth of sensitive information exposed

Before the issue was mitigated, tech news outlets managed to document the severity of the leaked data. Numerous private and sensitive documents were completely exposed on the search engine, including:

  • Detailed patient medical records along with real-world clinical trial results.

  • Contact lists containing the full names and phone numbers of elementary school students.

  • Internal business documents and performance reviews tied to employees' personally identifiable information.

  • Proprietary source code and critical work notes from developers.

Notably, among the exposed links was a conversation flagged as shared by Anthropic’s own system, revealing that Claude had generated explicit or pornographic content. This directly violates the strict acceptable use policies Anthropic has publicly declared. While bypassing chatbot filters through jailbreaking, repetitive prompts, or sophisticated prompt engineering is a widespread challenge across large language models (LLMs) today, the exact reason why this specific content appeared in the leak remains unclear.

Explanations from Anthropic and Google

When questioned about the incident, Anthropic appeared to place the bulk of the responsibility on users. A company representative stated that these shared links only surface on Google when users actively post them in public spaces where search engine crawlers can scan them (such as public forums or social media networks). Anthropic asserted that they do not automatically expose chat directories or sitemaps to search engines, and if a user only shares a link privately with someone, the URL remains completely secure.

Conversely, Google provided a clear response regarding its operational mechanisms. A Google spokesperson emphasized that they do not dictate which web pages are published on the internet. The search engine's role is to index everything that is publicly available online, and they always respect data crawling restrictions or exclusion commands (like robots.txt) set by website owners.

Fortunately, as of Monday afternoon, test queries using the advanced search operators no longer returned any results. This indicates that the leak has been addressed and mitigated by the involved parties.

History repeating itself and how to audit your account

This is not the first time AI assistants have faced this type of security challenge. Last year, a similar incident was documented when search engines crawled hundreds of Claude conversations before they could be removed. Going back further, a security researcher once harvested up to 100,000 conversations from ChatGPT’s public sharing feature.

This latest incident serves as a valuable reminder for anyone incorporating AI into their daily workflows. To safeguard your sensitive data, you should proactively review the list of shared links you have generated.

In the Claude interface, navigate to: Settings -> Privacy -> Shared Chats. From here, you can easily manage and review your entire sharing history, deleting any links that are no longer necessary to ensure the absolute security of your information.

Reference:

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page