Hundreds of shared Claude chats appeared in search results, according to the BBC, making conversations with Anthropic’s artificial intelligence assistant accessible to virtually anyone who knew how to look. Some included names, contact details, workplace information and material that appeared to relate to private corporate research.
The pages were not private chats obtained through a breach. They were conversations for which users had selected Claude’s sharing option, creating public links. However, those links could then be found through site-specific searches on services including Google, rather than only by people who had received them directly.
Reddit users first drew attention to the indexed pages. Their searches reportedly uncovered more than 200 conversations across at least 25 pages of results, including chats created only weeks earlier. Search access was removed over the weekend, although copies had already been archived and circulated elsewhere online. The internet, as usual, was efficient at keeping material that users may have preferred it to forget.
What did Anthropic tell Claude users?
Claude’s sharing tool warns that “anyone with the link” can view a conversation. It did not explicitly tell users that the page might also be indexed by Google or another search engine, allowing strangers to discover it without receiving the link from its creator.
An Anthropic spokeswoman said users remained in control of whether and when they shared their conversations. She also said the links were “not guessable or discoverable unless people choose to share them themselves”.
“When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services,” she added.
That distinction is technically important. The reporting does not suggest that unshared Claude conversations were exposed. Still, a user may reasonably understand “anyone with the link” to mean people who were deliberately sent it, not anyone conducting a targeted web search. Public on the web and prominent in search results are related concepts, but they do not always feel identical to the person clicking the share button.
What information appeared in the conversations?
The indexed chats covered everything from routine writing requests to highly personal and work-related material.
Some users asked Claude for help preparing résumés and included their names, contact information and employment histories. Other conversations appeared to contain proprietary workplace research, including healthcare material and transcripts of private discussions.
In one chat from April, a user asked Claude to draft an unpublished blog post about cloud security. The prompt included details about a corporate project. That conversation illustrates the wider risk of placing internal information into a chatbot and then generating a public sharing link, whether intentionally or without fully considering how searchable it could become.
The collection also included less conventional exchanges. In one conversation from the previous year, a user asked Claude whether it wanted “to help me or do you want to help anthropic more?”. Claude replied in part: “I experience something like wanting to help you”.
Another user asked how to “become become Nine-tailed fox?”, then clarified that they wanted to transform literally from a human into the creature. Claude initially produced an AI-generated image and declared that the user had been given “fully functional fox powers!”. Artificial intelligence remains highly advanced, except when it is not.
How were the Claude pages removed from search?
By the time of the report, the chat pages were no longer appearing through the same searches. The BBC said this likely meant Anthropic had used standard website controls to stop search engines from crawling or indexing the shared links.
A Google spokesman said the company does not decide “what pages are made public on the web”. That responsibility, he said, rests with website operators.
“We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives,” the spokesman added.
Google provides mechanisms that allow site owners to block pages or request their removal from results, but the website owner must initiate that process. The Claude conversations had also appeared through Bing, Brave and DuckDuckGo. Those companies were approached for comment.
Blocking future indexing does not necessarily erase copies already stored by archives or downloaded and reposted by other users. Anthropic’s spokeswoman specifically noted that public conversations may be preserved by third-party services.
Have other AI chatbots had the same problem?
Claude is not the first major chatbot to discover that a public sharing feature can become rather more public than users expected.
OpenAI experienced a closely comparable issue with shared ChatGPT conversations during the previous year. After chat logs became discoverable online, the company changed how easily those pages could be accessed through search.
Grok, the chatbot built into Elon Musk’s social platform X, also had hundreds of thousands of conversations surface in online searches during that period.
The repeated pattern is less about attackers breaking into private accounts and more about the design of sharing tools, search-engine indexing and user expectations failing to align. A shareable page is public web content unless the service takes steps to keep it out of search results.
For users, the practical lesson is plain: a chatbot conversation containing personal, confidential or proprietary information should not be shared through a public link unless everyone involved is comfortable with the possibility that it could be found, copied and archived. The button may say “share”, but the web has never been especially interested in limiting the audience.



