🟠 High  |  Source: Schneier on Security


Claude AI conversations shared via public links are being indexed by Google, exposing sensitive user data including cryptocurrency wallet keys, personal addresses, and medical billing information. The root cause is users enabling public sharing on their conversations, which Anthropic says is working as intended. However, the lack of clear user awareness around indexability means sensitive data is being inadvertently published to the open web.

Security Architect’s Take: If your organisation uses Claude or any similar AI assistant platform, audit whether users have public sharing enabled on conversations — especially in contexts where sensitive business or personal data is discussed. Enforce acceptable use policies that explicitly prohibit sharing AI chat sessions containing credentials, PII, or confidential data, and consider whether your AI tooling choices include sufficient data governance controls.

Original advisory: Some Claude Chats Are Searchable on Google