For the last week, Google has been quietly capturing a bunch of other people’s private conversations through the “share” button on Claude. Normal search results showed medical records, kids’ phone numbers, and internal company files. Anthropic’s public statement is that this is exactly what sharing is meant to do.
None of it was hacked in.
Reddit users spied it over the weekend. As of this was confirmed on the morning of July 27, 2026, the results were live.
All of this was done via Claude’s own sharing feature that generates a link that the app claims can be viewed by “anyone with the link.” Reviewers found the full medical record of a real patient, results from a clinical trial with patient names attached, documents listing the names and phone numbers of children in primary school, company documents marked “internal use only,” and performance reviews that contained personal details about the people being reviewed. The warning that users get before clicking share doesn’t even mention Google or any search engine.
Imagine what that means for the people involved. Having the name of a clinical trial patient sitting in a Google result isn’t only embarrassing. That’s the sort of thing an employer, an insurer, or a nosy ex could track down in the time it takes to type in a query. That’s worse. A kid’s phone number next to their name and school. Nothing of that requires anyone to be a hacker. You just have to know the right search string.
Nobody knows how many people actually understood that distinction.
That’s an inference, not a head-count, and some of the exposed material looks like it was intended for one co-worker or one doctor’s office, not the whole internet. It’s a reasonable guess that plenty of the people who clicked share didn’t realise a search engine could end up holding a copy. No one has proved that for every account involved. It just lines up with what was found.
Anthropic’s Defence
Asked to explain itself, Anthropic was more clarifying than apologising. The company says it puts people in charge of how they share their chats, that it doesn’t hand chat directories or sitemaps to search engines, and that a share link will only become discoverable if the person holding it puts it somewhere public. “Once that happens, in Anthropic’s framing, the content is now accessible to the public, just like anything else posted to the open web, which means it can be archived by other services the same way public content always is.
All of that is defensible. None of that gets at the real complaint.
Again, the complaint: Users are never told before they click share that a search engine may get a copy. It just says anyone with the link can see. Whether that omission is adequate disclosure is debated. Anthropic thinks so, for sure. Privacy advocates, and the people whose internal HR reviews are now in a search index, would probably tell you differently.
The Forbes Replay
This isn’t the first time Anthropic has gone through this same story. A previous Forbes investigation revealed that search engines had indexed hundreds of chats from Claude, which Anthropic took down after the fact. One detail from that round is worth sitting up for. Reporters found at least one user whose material from Claude was showing up in Google results, and that user said they never shared it themselves.
Perhaps that user forgot. Maybe a link was passed on somewhere they didn’t expect. Or perhaps the gap between what people think “share” means and what it actually does is wider than Anthropic is willing to admit.
None of that has been proven.
But usually, a company doesn’t get a second version of the same headline unless something underneath it is still broken. An indexing error is one mistake. The first one already made headlines; a second, on the same feature, starts to look like a company that treats its own privacy warnings as a formality rather than a design requirement.
Anthropic is not the only one to have played this game. Google is now able to search some shared chat logs from OpenAI’s ChatGPT and xAI’s Grok. This isn’t a defence, so much as a trend. A whole class of AI products, made by companies that compete on just about everything else, keeps ending up in the same failure mode: a share button that silently acts as a publish button in the wrong circumstances. That doesn’t make Anthropic’s version any less of a problem. The industry has collectively decided, though never actually saying so, that “share” is one of the more dangerous verbs in a chatbot’s interface.
If you’ve used Claude to draft anything that has a real name, a real diagnosis, or a real kid’s contact info sitting in it, the advice going around this week is about insultingly simple. Do not use the share button for anything sensitive. Copy the text out. Put it in a document you really control. Share that instead.
A warning label doesn’t cure it.
It’s a way to shift the blame from the company that made the button to the person who clicked it, and Anthropic has now done that twice.
The second time isn’t allowed to be a bug.


