PrivacySignal
Breach

Some Claude Chats Are Searchable on Google

Schneier on Security · · International · Data Breaches

Private conversations from Claude, Anthropic's AI assistant, are appearing in Google search results. The exposed content reportedly includes sensitive personal data such as cryptocurrency wallet keys, home addresses, medical billing details, and therapy-related notes — apparently because a user-level data-sharing setting made those chats public.

Why this matters: People typed things into an AI chat that they clearly meant to keep private. Therapy notes. Medical records. Crypto keys. Home addresses. That information is now indexed and searchable by anyone with Google. Anthropic's response is essentially: users had a setting, users are responsible. That is a defensible legal position and a bad one in practice. Most people do not read privacy settings carefully before they tell an AI something sensitive. If a product is designed around sharing personal data, the default matters enormously — and so does how clearly the risk is communicated before someone types the thing they cannot take back.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
The Record · · International

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

Switzerland's Federal Office for Information Technology and Communications disclosed a breach of its systems, with around 200 accounts compromised. The agency detected anomalies in on-premises Microsoft servers and suspects SharePoint vulnerabilities may have been the entry point, though the exact method has not been confirmed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Republican attorneys general urge OpenAI to preserve records on Hugging Face breach

Fifteen Republican attorneys general have written to OpenAI CEO Sam Altman requesting that the company preserve records related to a breach involving Hugging Face, suggesting OpenAI's conduct in the incident may have run afoul of state or federal law.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
DataBreaches.net · · International

Swiss federal IT office hit by cyberattack

Switzerland's Federal Office of Information Technology, Systems and Telecommunication reported a cyberattack on its SharePoint servers, resulting in roughly 200 compromised accounts and the blocking of external internet access to those systems. Authorities said there is currently no evidence of broader data exfiltration beyond the affected accounts.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
R Reuters · · International

US House panel seeks briefing on OpenAI's AI agent security breach

A US House committee has requested a briefing from OpenAI following a reported security breach involving its AI agent systems. The congressional inquiry signals growing legislative attention to vulnerabilities in agentic AI products.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →