Thousands of user conversations shared through Anthropic's Claude and xAI's Grok chatbots were discovered indexed and publicly searchable on Google in late July 2026, exposing personal information including resumes, financial spreadsheets, apparent Social Security numbers, cryptocurrency wallet credentials, and patient names. A Reddit user first identified the exposure by running the search query "site:claude.ai/share," which surfaced hundreds of publicly accessible Claude conversations that users had believed were private or limited to whoever held the share link.

The root cause was a configuration gap rather than a traditional security breach. Anthropic's link-sharing feature generated public web pages for shared conversations, and while those pages carried a robots.txt disallow directive, they lacked the separate noindex meta tag search engines require to avoid indexing content. That gap allowed Google to crawl and index shared conversation pages even though the disallow rule was intended to keep them out of search results.

Anthropic updated its technical controls and the exposed results were removed from Google search by July 28, according to reporting on the incident. By that point, however, a GitHub repository had already archived 453 Claude conversations and 519 Grok chats, totaling 11,241 messages in plain text. The incident echoed a similar exposure involving Grok's shared-chat feature in 2025, when hundreds of thousands of conversations were bulk-indexed by search engines in a comparable configuration failure.

Source: TechCrunch -- https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/