logo

Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say

ID: 77c5ff0d-1890-55ff-8ad4-004986e7df56

STIX ID: report--77c5ff0d-1890-55ff-8ad4-004986e7df56

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-18

Date Updated: 2026-04-21

Author: Dhivya

...
...

Fiverr inadvertently exposed sensitive customer files (including completed tax forms) after misconfiguring its Cloudinary file-hosting integration to generate public, indexable URLs; Google indexed these files and a researcher, after an unacknowledged 40-day responsible disclosure, published the findings on Hacker News. The report warns of identity theft and regulatory implications and recommends immediate steps: halt sensitive file transfers, implement signed/time-limited URLs, request search de-indexing, and monitor for fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.