Skip to main content

New announcement. Learn more

07 213 0982
TAGS

Sharing Is Caring, Until It's Your Client's Data on Google

A Reddit user typed a simple search into Google in July and found something that wasn't supposed to be there. A stranger's private conversation with an AI chatbot, complete with names, addresses, internal company notes and even a set of cryptocurrency wallet keys.

It happened on one of the major AI chatbots, and it's worth five minutes of any business owner's time, because the mistake behind it is one your own team could just as easily make.


The Key Takeaways

  • A popular AI chatbot's Share feature turns a private chat into a public web link. Some of those links got indexed by Google.

  • Exposed content included medical records, patient names, children's phone numbers, internal company documents and staff reviews.

  • A similar incident the year before hit around 600 conversations. This time, the number was described as "untold."

  • This isn't a one-off. Grok, Meta AI and ChatGPT have all had their own version of this in the last 18 months.

  • The fix stopped the indexing, but the exposure had already happened, and the habit behind it hasn't gone anywhere.


The "Private" Link That Isn't Private

The Share feature on tools like this hands you a link marked "anyone with the link can view," which reads like limited access. In practice, once that link lands somewhere public, a forum post, a support thread, a social share, search engines find it, crawl it and index it, and from there it's just one Google search away from anyone.

Anthropic told TechCrunch the links "only appear in search results when they've been posted somewhere search engines can see," and a spokesperson added they're "not guessable or discoverable unless people choose to share them themselves" [1]. Both statements are accurate, and neither changes what actually turned up: medical files, business documents, conversations people clearly assumed were private [1][2].

By the Monday after, the specific search trick people used to find these chats stopped working, though that only fixed how findable they were. Anyone who already had a link, or had already found and saved one, kept access regardless [2].

Your Front Door, Online

Most of the coverage on this focused on individual users caught out. For a business, the risk sits somewhere else: your staff decide what goes into these tools, and what leaves the building afterwards.

We've written before about staff accidentally pasting confidential data into AI tools without realising the risk. This is the second half of that same problem. What happens when someone shares an AI chat afterwards to a colleague, a client, a contractor, without checking who else that link could reach?

Most security failures follow the same shape, someone hands over the keys rather than has them taken. A share button that feels private but isn't works the same way.


Four Rules Before Your Team Hits Share

  1. The Risk: treating an AI chat like a private conversation. The Satori Rule: if you wouldn't put it in an email to a stranger, don't put it in a prompt. Client names, financials, health information, passwords, none of it belongs in a general-purpose AI tool.

  2. The Risk: not knowing what "shared" actually means. The Satori Rule: before you click share on anything, know exactly what "anyone with the link" means for that tool, and whether the link can be found without being sent directly.

  3. The Risk: running sensitive work through a personal, free account. The Satori Rule: move it to a business-grade plan. Personal chat accounts don't come with the admin controls, audit trails or data-handling terms a business plan does.

  4. The Risk: not actually knowing which AI tools your team is using. The Satori Rule: run a quick shadow AI check across the business. Most owners are surprised by the answer. Then set a plain-English policy on what can and can't go into them.


AI tools aren't off the table because of one bad use case. Used well, they're a genuine advantage and tool in the toolkit. The gap between a business that gets burned by a story like this and one that doesn't comes down to whether the guardrails are as deliberate as the tool itself.

If you're not sure what your team's been sharing, or where, that's worth checking before it becomes a headline. Get in touch and we'll talk you through where your business actually stands.


Sources

[1] TechCrunch, "PSA: Your Claude shared chats and Artifacts may have ended up on Google," 27 July 2026, https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/

[2] Malwarebytes, "Shared Claude chats were searchable on Google," 28 July 2026 (updated 3 August 2026), https://www.malwarebytes.com/blog/privacy/2026/07/shared-claude-chats-were-searchable-on-google