Your Claude Chats May Be Public

— by

I did something a little uncomfortable last week: I ran a search to check whether any of my own Claude artifacts were sitting out in the open on the internet. Turns out, for a lot of people, they were.

On July 25th, someone ran a simple Google search — just the word “site,” a colon, and Claude’s share URL — and pulled up hundreds of other people’s private conversations and Artifacts. Social Security numbers. API keys. Financial models. Résumés. Nobody hacked anything. Every single one of those pages was already public. The people who shared them just didn’t know it.

What actually happened

Here’s the mechanism, and it’s worth understanding because it’s not new — it’s just wearing a new outfit. Claude’s share feature generates a public webpage for a conversation or Artifact whenever someone selects “anyone with the link.” Those pages weren’t tagged to keep search engines out. So once a link existed anywhere a crawler could find it — posted in a forum, bookmarked somewhere, linked from another page entirely — it got indexed exactly like any other public webpage.

This is the same failure mode that’s tripped people up for over a decade with “unlisted” Google Docs and YouTube links. A link with no visible directory listing feels private. It isn’t. It’s just undiscovered — until it isn’t.

Google had pulled roughly 600 indexed results by July 26th. But here’s the detail that matters more than the headline number: delisting from search and revoking a link are two different things. If someone bookmarked a URL before it disappeared from search results, that page may still open exactly like it did before — unless the platform revokes access on its end.

Why this isn’t just a Claude story

I want to be clear about what this was and wasn’t. Nothing suggests anyone’s account got broken into. Every exposed conversation was something a person chose to make public, using a share setting they probably didn’t fully register as “public.” That distinction matters, because it means the fix isn’t about better passwords — it’s about understanding what “share” actually does before you click it.

Think about it like leaving a folder in an unlocked filing cabinet in a public hallway. Nobody broke the lock — there wasn’t one. Nobody stole the folder. It just sat there, technically accessible to anyone who happened to walk by, until someone did, and noticed what was inside.

And here’s the part that should actually worry you if you run a firm: this isn’t only a today problem. If someone on your team shared a Claude conversation with client data in it two years ago — before you’d even released an AI policy — that link could still be sitting there, live, right now. An audit here has to look backward, not just forward.

What this means for accountants

Your confidentiality obligation under AICPA standards doesn’t care what tool the data passed through. It doesn’t distinguish between “I didn’t mean for this to become public” and “it was technically public the whole time.” Both are the same fact pattern from a professional-standards perspective. If anyone at your firm has shared an AI conversation touching client PII, financial data, or work product, that’s worth finding and revoking — not eventually, this week.

There’s also a vendor-diligence lesson buried in here. Most firms, when they vet an AI tool, ask about login security — who can access the account, how authentication works. That’s the wrong single question. Ask specifically how the tool’s sharing feature handles indexing and default visibility. Is a shared link private by default, or public by default? Can you actually revoke it, or does revoking just remove it from search? One useful data point: Claude Enterprise and Teams accounts default share links to “within your organization only,” with access control built in. Individual accounts default to “anyone with the link” — which is exactly the setting behind this incident.

Key Takeaways

  • On July 25th, a single Google search surfaced hundreds of shared Claude conversations and Artifacts — exposing SSNs, financial models, and API keys.
  • Nothing was hacked. Every exposed item was made public by the person who shared it, usually without realizing it.
  • Google removed roughly 600 results by July 26th, but delisting isn’t revoking — a saved link may still open.
  • Enterprise and Teams accounts default to organization-only sharing with access control; individual accounts default to “anyone with the link.”
  • This week’s action: audit every AI share link your firm has ever created — not just recent ones — and revoke anything touching client data.

Before you share anything from an AI tool again, ask yourself one question: would you be comfortable if this exact page showed up in a Google search next week? If the answer is no, don’t hit share until you know what “share” actually does in that tool.

Want the CPE credit? Take the full lesson on EverydayCPE and earn 0.2 CPE credits: Your Claude Chats May Be Public

Today’s lesson


Leave a Reply

Discover more from EverydayCPE

Subscribe now to keep reading and get access to the full archive.

Continue reading