What happened?
Hundreds of conversations with Anthropic’s Claude AI chatbot were found in results from Google and other search engines, including Bing, Brave and DuckDuckGo as reported by Cyber News. Reddit users initially discovered the material using site specific searches. More than 200 conversations reportedly appeared across at least 25 pages of search results, although the total number of affected users remains unknown. Some indexed conversations had taken place only weeks before the discovery.
The exposure affected conversations and artefacts that users had published using Claude’s “Anyone with a link” sharing option. This creates a separate URL containing a snapshot of the conversation up to the point at which it was shared. Although these URLs were not designed to be easily guessed, they could be indexed after being published or shared somewhere accessible to search engine crawlers. The issue therefore appears to have been an unintended public disclosure rather than a cyber-attack or compromise of Anthropic’s internal systems.
The publicly accessible material reportedly included names, contact details, CVs, corporate project information, proprietary research and transcripts of private conversations. Other reports identified potentially more sensitive material, including clinical and healthcare information, location data, apartment access codes, API keys, cryptocurrency wallet details and US Social Security numbers. Some of these reports have not been independently verified, but they illustrate the type of information users may include in AI conversations and artefacts.
Anthropic stated that users control whether to share their conversations and that shared URLs are not ordinarily discoverable unless users publish or distribute them. However, critics argued that the wording “Anyone with a link” did not clearly communicate that conversations could appear in search engine results.
Search engine access to the conversations was reportedly removed over the weekend according to the BBC, suggesting that Anthropic may have implemented measures to prevent further indexing. However, copies had already been archived and circulated online, meaning removal from search results may not eliminate all copies. In fact, using the search term "site:claude.ai/public/artifacts" in Google still returns a list of results. Google stated that website owners control whether public pages can be crawled or indexed and that it respects the technical directives they provide.
So what?
The incident demonstrates that any information that can be entered into AI software should be carefully considered to avoid disclosure and configuration settings checked to ensure that this information remains private. Once a link is posted on a public website, social media platform or third-party directory, it may be found by search engine crawlers, indexed and subsequently archived. Removing the original page or search result may not remove copies already cached, downloaded or redistributed.
The exposure highlights a mismatch between users’ expectations and the practical meaning of link-based sharing. Users may reasonably interpret “Anyone with a link” as meaning that only people who receive the URL can view the content, rather than that it could appear in public search results. Clear warnings, secure default settings and separate options for private link sharing and public publication are therefore important. Technical measures such as no index directives could reduce accidental discovery, although they are not a substitute for authentication and proper access controls.
The incident also illustrates the risks of entering confidential information into generative AI services. AI conversations may contain personal data, commercially sensitive material, intellectual property, credentials, legal documents or private workplace discussions. If this information becomes publicly accessible, organisations could face identity theft, account compromise, loss of intellectual property, breach of confidence, contractual disputes, reputational damage and regulatory scrutiny. Exposed API keys, cryptocurrency details or access codes could also facilitate further security incidents.
This does not represent a new attack technique or an intrusion by an identified threat actor. Instead, it reflects a recurring information governance weakness involving public sharing features, unclear user expectations and search engine indexing. Similar incidents involving ChatGPT and Grok suggest a broader industry issue rather than a problem unique to Claude.
For organisations, the incident increases the risk associated with unsupervised use of generative AI. Risk assessments should account not only for what employees enter AI tools, but also how conversations and outputs are stored, shared and published. Organisations that do not govern public links, approved AI services and the handling of sensitive information may face a higher likelihood of accidental data disclosure.
What should I do?
Organisations should identify whether employees have used Claude’s “Anyone with a link” feature. Review account records, browser histories and collaboration platforms for Claude URLs, and search online using the organisation’s name, email domains and project names. Revoke any links that are unnecessary or contain sensitive information.
If information has been exposed, determine what was accessible, for how long and who may have accessed it. Preserve relevant URLs, screenshots and logs before requesting removal from search engines, archives and third-party websites. Bear in mind that removing search results will not erase copies that have already been cached, downloaded or redistributed.
Treat exposed credentials as compromised. Revoke or rotate API keys, passwords, authentication tokens and cryptocurrency credentials; change physical access codes; and contact financial institutions if banking or payment information was involved. Monitor affected accounts and systems for suspicious activity.
Manage the matter through established security and personal data breach procedures. Information security, legal, privacy and compliance teams should assess whether personal, privileged, confidential or commercially sensitive information was disclosed.
Organisations should establish clear rules for generative AI use. Employees must not enter sensitive information into unapproved AI services, and public sharing should be restricted where possible. Staff should understand that a Claude link may include all earlier messages and artefacts, not only the item they intended to share. These requirements should be included in acceptable use, data protection and information classification policies.
Technical controls should include data loss prevention, monitoring of generative AI services and an inventory of approved tools. Similar platforms should prevent public pages from being indexed by default by using measures such as no index directives and X-Robots-Tag headers. However, these measures do not replace authentication and appropriate access controls.
IT and security teams should confirm whether public Claude links can be identified and disabled, whether sensitive information or active credentials were exposed, and whether monitoring and incident response procedures adequately cover AI services and AI-hosted content.