Post

HN
Hacker News (Newest)

Fiverr Denies Report of Data Leak

Freelance services marketplace Fiverr denied a media report that it leaked sensitive data.

The company made the denial in a reply to a Cybernews post on X that invited readers to โ€œLearn what sensitive documents are leaked.โ€

In the article to which its post linked, Cybernews reported that an anonymous security researcher with the alias โ€œ morpheuskafka โ€ said in a post on Hacker News that a publicly exposed instance of storage service Cloudinary that likely belonged to Fiverr was leaking Fiverr usersโ€™ invoices, tax return forms, driverโ€™s licenses, credentials and other sensitive documents.

The Cloudinary platform, which is used for uploading and storing files, has support for signed/expiring URLs, but Fiverr uses public URLs for communication between clients and workers, according to the report.

Cybernews reported that it confirmed that many of the documents had been indexed by Google and that search results from affected web servers returned sensitive information with personally identifiable information (PII). The report added that users on the Hacker News forum shared links to such documents.

โ€œThis is a major security lapse by Fiverr, due to the links being publicly accessible and indexable, a lot of resources are already being indexed by Google,โ€ Aras Nazarovas , information security researcher at Cybernews, said in the report. โ€œEssentially all files that were shared between service buyers and sellers, including personal identity documents, sensitive contracts, passwords, and API keys shared with contractors, finished and work-in-progress deliverables.โ€