Some Claude Chats Indexed by Google Expose Personal Data and Crypto Keys
What Happened — Anthropic’s Claude AI generated chat links that users can share publicly were inadvertently indexed by Google, making private conversation content searchable. The exposed material includes therapy‑session notes, medical‑billing dashboards, personal addresses, and cryptocurrency wallet private keys.
Why It Matters for Compliance & Audit Readiness
- Unintended public exposure of personal data directly challenges privacy controls required by GDPR, CCPA, and SOC 2 CC6 (Privacy).
- Demonstrates the need for continuous monitoring of data‑sharing settings and evidence that consent and disclosure policies are enforced and auditable.
- Highlights the importance of having a documented, testable process for responding to data‑subject requests and for proving privacy‑by‑design in AI‑driven services.
Who Is Affected
- SaaS AI platform providers (API/Chatbot services)
- Healthcare‑tech and fintech users of AI‑assisted tools
Recommended Actions
- Review and tighten default sharing settings; enforce “opt‑in” for any public link generation.
- Map the incident to SOC 2 CC6 controls (privacy notice, data‑subject rights, data retention) and capture evidence of policy enforcement.
- Conduct a privacy impact assessment (PIA) for AI chat features and update DSAR response procedures. Source: https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html
Technical Notes — The exposure stems from user‑controlled shareable URLs that were not protected against search‑engine crawling; no vulnerability in Anthropic’s code was identified. Data types leaked include PHI, PII, and cryptocurrency private keys. Source: https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html