Fiverr is facing scrutiny over reports that thousands of sensitive user files were publicly accessible online through Cloudinary-hosted URLs that could be indexed by search engines. Reported exposed material included tax forms, driver's licenses, work contracts, passwords, API keys, tax records, and private work deliverables. A security researcher said Fiverr was notified about the issue roughly 40 days before public disclosure, while reports alleged the files were stored with public links instead of restricted or expiring access controls.
Fiverr denied that the incident constituted a data breach and rejected allegations that it exposed user data, arguing that users had consented to share documents for marketplace transactions. Security experts challenged that position, saying consent to exchange files with counterparties does not equate to consent for unrestricted public internet exposure. The incident remains disputed, but the reports have raised concerns over third-party cloud storage practices, search engine indexing of sensitive documents, and potential risks of identity theft and credential compromise for affected users.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Fiverr rejected claims that it had suffered a data leak or security breach, arguing that users had consented to share files for marketplace purposes. Outside experts disputed that interpretation, saying transaction-related sharing does not imply unrestricted public exposure.
Reports stated that thousands of Fiverr-related files, including IDs, tax forms, contracts, passwords, API keys, and private work deliverables, were publicly accessible online due to storage practices involving a third-party cloud service. The exposure was described as an allegation rather than a confirmed breach.
A security researcher said Fiverr was notified about publicly accessible sensitive files roughly 40 days before the issue was publicly disclosed, but did not receive a response. The files were allegedly exposed through publicly reachable Cloudinary URLs that could be indexed by search engines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.