PrivacySignal
Breach

Some Claude Chats Are Searchable on Google

Schneier on Security · · International · Data Breaches

Private conversations from Claude, Anthropic's AI assistant, are appearing in Google search results. The exposed content reportedly includes sensitive personal data such as cryptocurrency wallet keys, home addresses, medical billing details, and therapy-related notes — apparently because a user-level data-sharing setting made those chats public.

Why this matters: People typed things into an AI chat that they clearly meant to keep private. Therapy notes. Medical records. Crypto keys. Home addresses. That information is now indexed and searchable by anyone with Google. Anthropic's response is essentially: users had a setting, users are responsible. That is a defensible legal position and a bad one in practice. Most people do not read privacy settings carefully before they tell an AI something sensitive. If a product is designed around sharing personal data, the default matters enormously — and so does how clearly the risk is communicated before someone types the thing they cannot take back.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

The true cost of a ransomware attack, with and without BCDR

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

xHealth Data Breach Affects 118,000 Individuals

zHealth, a software company that provides practice management and electronic health records tools to medical practices, has disclosed a data breach affecting approximately 118,000 people.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

Payroll system of mosques, madrasahs hit by ransomware; staff details potentially compromised

David Sun reports: The payroll system of mosques and madrasahs overseen by the Islamic Religious Council of Singapore (MUIS) has been hacked and held for ransom, The Straits Times has learnt. The SmartHRMS human resources (HR) system is supplied by Singapore-based software vendor Avelogic. The latest cybersecurity incident notice on Avelogic’s website, which was last... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →