Fiverr Denies Report of Data Leak
Freelance services marketplace Fiverr denied a media report that it leaked sensitive data.
The company made the denial in a reply to a Cybernews post on X that invited readers to โLearn what sensitive documents are leaked.โ
In the article to which its post linked, Cybernews reported that an anonymous security researcher with the alias โ morpheuskafka โ said in a post on Hacker News that a publicly exposed instance of storage service Cloudinary that likely belonged to Fiverr was leaking Fiverr usersโ invoices, tax return forms, driverโs licenses, credentials and other sensitive documents.
The Cloudinary platform, which is used for uploading and storing files, has support for signed/expiring URLs, but Fiverr uses public URLs for communication between clients and workers, according to the report.
Cybernews reported that it confirmed that many of the documents had been indexed by Google and that search results from affected web servers returned sensitive information with personally identifiable information (PII). The report added that users on the Hacker News forum shared links to such documents.
โThis is a major security lapse by Fiverr, due to the links being publicly accessible and indexable, a lot of resources are already being indexed by Google,โ Aras Nazarovas , information security researcher at Cybernews, said in the report. โEssentially all files that were shared between service buyers and sellers, including personal identity documents, sensitive contracts, passwords, and API keys shared with contractors, finished and work-in-progress deliverables.โ