Jul 26, 2026 · 12:41 PM
Subscribe
Home Ai

Claude shared chats have been indexed by Google and anyone with a search bar can find them

Roughly 600 Claude conversations were indexed by Google before Anthropic moved to remove them, and over 143,000 AI chatbot chats are sitting on Archive.org according to Obsidian Security research. AWS tokens, VC memos, and salary data have surfaced through basic search queries, while attackers have separately weaponized Claude's shared-chat URLs to distribute macOS malware.

Walter Schulze
· 5 min read · 567 reads
Claude shared chats have been indexed by Google and anyone with a search bar can find them

Claude shared chats have already shown up in Google, and the wider archive problem is larger than one chatbot. If you've used share links for sensitive work, you should treat those links as public until you've checked them yourself.

If you've ever pasted a cap table, an AWS key, or a draft investor memo into Claude and hit share, don't assume the conversation stayed between you and the person who got the link. That's the problem. It didn't need to be hacked. A normal sharing feature created public transcript pages, and some of those pages found their way into search engines and archives.

Forbes reported in September 2025 that Google had estimated just under 600 Claude conversations were indexed before the visible results disappeared. Anthropic told Forbes that users control whether they share Claude conversations publicly and that the company actively blocks search crawlers from crawling shared chats. Those two facts can both be true. The mechanics are dull. The consequence isn't. Once a public URL exists, it can be posted elsewhere, captured by another service, preserved in an export, or saved by Archive.org before a platform change catches up.

Obsidian Security's separate Incident Watch report put the broader number at more than 143,000 publicly accessible GenAI chatbot conversations across services including Claude, Copilot, ChatGPT, Grok, Mistral, and Qwen. The report attributed the discovery to security researcher dead1nfluence and said the recovered material included AWS Access Key IDs, a Replicate API token, and other exposed content that could be useful to an attacker. Don't wave that away. One copied key in an old AI transcript can be more expensive than the embarrassment of the transcript itself. That calculates badly.

The types of material showing up are exactly what you'd expect. Founders, operators, lawyers, and investors actually use these tools for real work: confidential salary data, internal investment notes, legal analysis, customer context, code snippets, credentials, you name it. A search operator such as site:claude.ai plus a phrase like internal use only is not an advanced attack. It's a search bar.

A trusted link is now part of the threat

The indexing issue is only one side of the story. Zscaler Threat Hunting published research on July 15, 2026 describing a MacSync Stealer campaign that used paid Google ads to send people searching for Claude terms to shared Claude chats carrying ClickFix instructions. The chats looked more convincing because they sat on a real claude.ai URL. The domain did the work.

Zscaler said the campaign ran from June 12 to June 19, used 22 unique Google Ads campaign IDs, and targeted search terms such as claude, claude ai, claude code, and claude mac. The shared chats told visitors to paste commands into macOS Terminal. Those commands delivered MacSync Stealer, which Zscaler said can steal credentials, sensitive files, cryptocurrency wallet data, and more. The company also said the malicious shared chats were no longer accessible when it published the report.

Trend Micro, cited by The Hacker News, described a related Claude shared-chat abuse campaign and said the Asia-Pacific region accounted for 67.2% of confirmed victims, with Taiwan representing 30.5% of total traffic. The important point for you is narrower than the geography. Claude itself wasn't compromised. Attackers used a legitimate collaboration feature to make a malicious instruction page feel safe.

Anthropic has also been tightening the policy layer around Claude. Its privacy update, published June 8 and effective July 8, 2026, applies to consumer Free, Pro, and Max accounts and adds language around multi-step tasks, connected apps, and verification data. Anthropic's help center says identity verification may ask for a government-issued photo ID and a live selfie through Persona in some circumstances. That's real movement. It still doesn't erase a transcript that has already been copied elsewhere.

What you should do right now

Start with the obvious. Open your Claude privacy settings, review shared chats, and unshare anything that contains credentials, financials, legal material, customer data, or anything you wouldn't post in a public Slack channel. Shared means shared. If the conversation included an API key, don't merely delete the chat. Rotate credentials immediately.

If you're using Claude for legal work, be especially careful with consumer accounts. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York ruled in February 2026 that about 31 documents generated through the consumer version of Claude were not protected by attorney-client privilege or the work product doctrine. Debevoise and other law firms noted that the ruling turned on facts including the absence of attorney direction and the consumer privacy terms, so it doesn't settle every enterprise AI use case. But it is a warning you can actually use.

The deeper issue is that share features are usually designed for convenience first. That's not evil. It's how collaboration software spreads. But AI chats aren't only holding meeting notes and harmless drafts anymore. They're holding fund models, litigation theories, employee data, source code, and sometimes keys that open production systems.

Until Anthropic and every other AI platform makes shared-link control harder to misunderstand, the safest assumption is simple: if you create a public AI chat link, you should expect it to travel farther than you planned.

Also read: Georgia Power is seizing family homes to build AI data center power lines and residents are calling it theftSingapore's Ropedia raises $30M to teach robots how to do chores by watching humansChinese AI models are taking US market share and the price gap explains everything

TOPICS
Walter Schulze brings all the breaking news stories in the tech and startup world and to ensure that Startup Fortune offers a timely reporting on the trends happen in the industry. He now works on a part time basis for Startup Fortune specializing in covering tech and startup news and he also sheds light on investment opportunities and trends.
Related Articles
More posts →
Loading next article…
You're all caught up