AI Briefing
KO

Fiverr Left Customer Files Publicly Accessible and Searchable

·2026.04.15 13:32

Key point

Fiverr's public URL configuration exposed sensitive customer documents to Google search.

Details

Fiverr exposed PDF and image files exchanged via Cloudinary using public URLs instead of signed URLs, making hundreds of customer documents accessible through Google search.

The exposed materials included sensitive information such as Form 1040 tax returns, SSNs, API tokens, and health-related documents, along with even more vulnerable data mixed in, such as internal nonprofit reports and child therapy-related documents.

The security report was submitted 40 days ago but received no response, and Fiverr only began taking action after later recognizing it as a "second report." The community viewed this not as a simple mistake but as an example of structural security flaws and technical ignorance.

The key issues are as follows.

  • Use of Cloudinary public URLs: Public links were used instead of expiring signed URLs
  • Search exposure path: Indexed by Google through public HTML pages or sitemaps
  • Lack of response: No reply to security emails and delayed action
  • Regulatory risk: Possible violations of GLBA and the FTC Safeguards Rule were also raised

Although ISO 27001 certification and AWS security certification were mentioned, criticism followed that the actual file storage and distribution methods failed to support these certifications. This incident shows that even large platforms can lead to massive personal data breaches if they neglect basic file access controls.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.