Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fiverr Faces Data Breach Due to Cloudinary Misconfiguration

Fiverr Faces Data Breach Due to Cloudinary Misconfiguration

Posted on April 18, 2026 By CWS

Fiverr, a prominent freelance marketplace, is embroiled in a privacy controversy following revelations by researchers that personal customer files have been made publicly accessible through Google. The breach, highlighted on Hacker News, stems from a misconfigured file-hosting setup that exposed sensitive data, including tax forms, exchanged between freelancers and clients.

The Cloudinary Configuration Issue

The problem originated from Fiverr’s method of handling file exchanges within its messaging system. Fiverr utilizes Cloudinary, a third-party service, to manage and host images and documents, including completed work submitted to clients. Despite Cloudinary’s capability to create secure, time-limited links, Fiverr reportedly set up the service to generate publicly accessible URLs for sensitive files. This lack of protection allowed search engines like Google to index these files.

It appears that these public links were inadvertently exposed through unsecured HTML pages within Fiverr’s network. This oversight has severe implications, as specific searches on Google can reportedly reveal private documents, such as tax forms, containing essential financial data.

Regulatory and Security Concerns

The situation presents a stark contradiction, as Fiverr invests in Google Ads for tax-related services while failing to secure the sensitive outputs of such services. This lapse raises significant regulatory alarms, potentially breaching the Federal Trade Commission’s Safeguards Rule and the Gramm-Leach-Bliley Act, both of which demand rigorous protection of consumer financial information.

The researcher who uncovered the issue adhered to responsible disclosure practices, notifying Fiverr’s security team 40 days before making the findings public. However, due to the absence of a response or corrective measures from Fiverr, the researcher opted to release the information publicly to alert potentially affected users.

Recommendations and User Precautions

Until Fiverr addresses this security flaw, users remain vulnerable to identity theft and financial fraud. It is recommended that freelancers and clients cease the transmission of sensitive documents via Fiverr’s messaging platform. Additionally, Fiverr should promptly update its Cloudinary integration to use signed URLs that expire after download to safeguard transferred files.

The company must also act swiftly to request the removal of exposed directories from Google’s search index. Clients who have engaged in financial services on Fiverr should vigilantly monitor their credit reports for any unauthorized activity.

Stay updated on cybersecurity developments by following us on Google News, LinkedIn, and X. Reach out to us to feature your stories.

Cyber Security News Tags:Cloudinary, Cybersecurity, data breach, Fiverr, FTC, GLBA, Google indexing, PII, Privacy, Security

Post navigation

Previous Post: Grinex Exchange Halts After $13.74M Cyber Heist Linked to Intelligence
Next Post: Tycoon 2FA Loses Ground Amid Rising Phishing Threats

Related Posts

New DRAM Attack Threatens CPU Security Measures New DRAM Attack Threatens CPU Security Measures Cyber Security News
Vulnerability in TP-Link Kasa Devices Exposes Security Risks Vulnerability in TP-Link Kasa Devices Exposes Security Risks Cyber Security News
Langchain SSRF Vulnerability Threatens Internal Security Langchain SSRF Vulnerability Threatens Internal Security Cyber Security News
OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently Cyber Security News
ASUS Armoury Crate Vulnerability Let Attackers Escalate to System User on Windows Machine ASUS Armoury Crate Vulnerability Let Attackers Escalate to System User on Windows Machine Cyber Security News
New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark