{"id":12222,"date":"2026-04-18T10:03:42","date_gmt":"2026-04-18T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/fiverr-allegedly-leaks-user-information-to-google-indexing-researchers-say\/"},"modified":"2026-04-18T10:03:42","modified_gmt":"2026-04-18T10:03:42","slug":"fiverr-allegedly-leaks-user-information-to-google-indexing-researchers-say","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/fiverr-allegedly-leaks-user-information-to-google-indexing-researchers-say\/","title":{"rendered":"Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say"},"content":{"rendered":"<p>    Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by <a href=\"https:\/\/cybersecuritynews.com\/hackers-hijacking-google-search-results-via-backdoored-browser-extensions\/\" type=\"post\" id=\"4530\" target=\"_blank\" rel=\"noreferrer noopener\">Google search<\/a>. <\/p>\n<p>According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal identifiable information (PII), including completed tax forms, that were exchanged between freelancers and clients.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-cloudinary-misconfiguration\"><strong>The Cloudinary Misconfiguration<\/strong><\/h2>\n<p>The root of the data exposure lies in how Fiverr handles file sharing within its internal messaging system. <\/p>\n<p>The platform relies on a third-party service called Cloudinary to process and host images and PDF documents, including final work products delivered to clients.<\/p>\n<p>While Cloudinary operates similarly to an <a href=\"https:\/\/cybersecuritynews.com\/best-aws-monitoring-tools\/\" type=\"post\" id=\"37530\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon S3 digital storage bucket<\/a> and supports secure, expiring web links, Fiverr reportedly configured the service incorrectly. <\/p>\n<p>Instead of requiring authentication, Fiverr opted to generate fully public URLs for these sensitive attachments. Because these files were left open to the public, search engines like Google were able to crawl and index them. <\/p>\n<p>This suggests that the public file links may have been exposed through unprotected HTML pages somewhere on Fiverr\u2019s network.<\/p>\n<p>The impact of this oversight is severe, as anyone can allegedly use specific Google search queries to surface private documents. <\/p>\n<p>For example, running a site-specific search for \u201cform 1040\u201d on Fiverr\u2019s Cloudinary domain instantly reveals<a href=\"https:\/\/cybersecuritynews.com\/cybercriminals-abuse-irs-and-tax-filing-lures\/\" type=\"post\" id=\"146216\" target=\"_blank\" rel=\"noreferrer noopener\"> private tax documents <\/a>containing highly sensitive financial and personal data.<\/p>\n<p>Interestingly, the researcher highlighted a troubling contradiction. Fiverr actively purchases Google Ads for tax preparation services, yet the platform fails to secure the resulting financial work products. <\/p>\n<p>This exposure raises immediate regulatory concerns. By failing to lock down financial documents properly, the platform and its tax preparation freelancers could be in direct violation of the FTC Safeguards Rule and the Gramm-Leach-Bliley Act (GLBA), which mandate strict protections for consumer financial data.<\/p>\n<p><a href=\"https:\/\/news.ycombinator.com\/item?id=47769796\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The researcher who discovered the issue claims<\/a> to have followed standard responsible disclosure protocols. A detailed vulnerability report was sent to Fiverr\u2019s designated security team 40 days before the public release. <\/p>\n<p>After receiving no response or remediation efforts from the company, the researcher opted to publish the findings on Hacker News to warn affected users.<\/p>\n<h2 class=\"wp-block-heading\" id=\"key-takeaways-and-mitigations\"><strong>Key Takeaways and Mitigations<\/strong><\/h2>\n<p>Until Fiverr resolves this public exposure, users are at risk of <a href=\"https:\/\/cybersecuritynews.com\/christmas-phishing-surge-chains-docusign-spoofing\/\" type=\"post\" id=\"138852\" target=\"_blank\" rel=\"noreferrer noopener\">identity theft and financial fraud<\/a>. Both freelancers and clients should take immediate precautions:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Halt sensitive transfers:<\/strong>\u00a0Users should temporarily stop sending sensitive documents, such as tax forms or medical records, through Fiverr\u2019s messaging system.<\/li>\n<li>\n<strong>Implement signed URLs:<\/strong>\u00a0Fiverr must urgently update its Cloudinary integration to utilize signed, time-limited URLs for all user-to-user file transfers to ensure files expire after being downloaded.<\/li>\n<li>\n<strong>Request search de-indexing:<\/strong>\u00a0The company needs to issue urgent takedown requests to Google to remove the exposed domain directories from public search results.<\/li>\n<li>\n<strong>Monitor for identity theft:<\/strong>\u00a0Clients who purchased financial or tax preparation gigs on Fiverr should monitor their credit reports for unauthorized activity.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fiverr-allegedly-leaks-user-information-to-google\/\">Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fiverr-allegedly-leaks-user-information-to-google\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal identifiable information (PII), including completed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156,163],"tags":[130],"class_list":["post-12222","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","category-google","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12222"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12222"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12222\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}