You should check your settings in Claude because thousands of private conversations have leaked to the web

Reddit users discovered that thousands of Claude chats are accessible via Google search. The leak stems from the chat sharing feature, which resulted in sensitive data being indexed by search engines.

Source
You should check your settings in Claude because thousands of private conversations have leaked to the web
Photo: Geektime / תמונה: Unsplash

Photo: Unsplash

If you have recently used Claude to consult on a sensitive topic, write code, or check a medical document you received, you should check your settings. This past weekend, users on Reddit discovered that a simple Google search reveals thousands of conversations created within the popular chatbot from Anthropic.

According to a report on the 404Media website, these results included information that was supposed to remain completely confidential. Among other things, a detailed medical report with TMI (Too Much Information) of a real patient was exposed; results of clinical trials; trade secrets of companies; a draft of a blog post about cloud security that had not yet been published; resumes; and even phone numbers of minors. According to the report, in some cases, the language model even generated erotic content, in complete contradiction to Anthropic's policy. In one of the more bizarre chats, Claude was asked to help a user turn into a... "nine-tailed fox."

Of course, you don't have to be a hacker or an experienced information security researcher to find such chats — and we, too, in a simple Google search, were able to find chats and applications in Hebrew that were not intended to be public, yet are still available now in search engines.

Anthropic: You are using the sharing feature incorrectly

This embarrassing leak stemmed from Claude's chat sharing feature and the way it works. When you want to share a conversation, Claude does warn that anyone who receives the link will be able to view the chat, but most users assume — and it's hard to blame them — that it is a private link that only they can share, similar to sharing in Google Docs or a link to a private YouTube video that you upload, which are not supposed to reach search results on the web.

In practice, it turned out that links shared on various platforms were indexed directly by search engines without the users' knowledge, and suddenly became public domain. Anthropic was quick to throw the users under the bus, and a company spokesperson clarified that the links are indeed secret and cannot be guessed — unless the users chose to share them themselves in places exposed to Google's scanning and indexing. Google responded that its search engine does not control the content and operates according to the scanning settings set by website owners.

This is what you want to see. Screenshot: Geektime

And yet, after the scandal broke, Anthropic was quick to change the settings in the sharing feature, so that the links no longer appear in the results. It is worth remembering that this is not the first time such an event has occurred. In the past, we have already seen almost identical leaks in other models, such as in the case of OpenAI a year ago. All this proves once again that you need to be very careful with chatbots and your personal information — especially if you plan to share the results with someone.

To ensure this, it is recommended to check your account settings. Simply enter the settings menu, go to the privacy tab, and click on shared chats via the path Settings -> Privacy -> Shared Chats. There you will be able to see exactly which chats are defined as public and cancel their sharing immediately, until you see the message "No shared content found."

Related News