TL;DR: Fiverr stored user-uploaded files on Cloudinary using public, non-expiring URLs. Those URLs got indexed by Google. That means anyone could search site:fiverr-res.cloudinary.com form 1040 and pull up freelancers’ actual tax returns. Also exposed: driver’s licenses, contracts, API keys, and passwords. A security researcher reported it 40 days before it went public. Fiverr didn’t respond. When it finally did, it said this wasn’t a breach, just users “sharing files in the normal course of marketplace activity.” The company’s ISO 27001 security certification had expired at the time.
What Google Knew About Your Freelance Work
Here’s the search query that started it: site:fiverr-res.cloudinary.com form 1040.
Type that into Google, and you’d find actual IRS Form 1040 tax returns uploaded by Fiverr freelancers. Names. Social Security Numbers. Addresses. Income figures. All sitting on public Cloudinary URLs, all indexed by Google, all available to anyone with a search engine [1].
The tax forms were just the start. A security researcher using the handle Morpheuskafka discovered that Fiverr’s file-sharing system had turned the company’s entire document exchange into a public library. The exposed files included [1][2]:
- Tax forms: W-9s, 1040s, tax returns with SSNs and addresses
- Government IDs: driver’s licenses, identity documents
- Contracts: work agreements, NDAs, deliverables
- Credentials: API keys, passwords, login details
- Work-in-progress files: client deliverables meant to be private
Cybernews independently confirmed the findings [1]. This wasn’t a theoretical vulnerability. These documents were live, searchable, and had been for an unknown period.
The Unlocked Door Nobody Checked
Fiverr uses Cloudinary, a cloud-based media management platform, to handle file uploads in its messaging system. When a freelancer sends a client a document (a tax form for payment, an ID for verification, a contract for review) Cloudinary stores and serves that file.
The problem: Fiverr configured those uploads as public, non-expiring URLs. No authentication required. No time limit. No access controls. Anyone with the link could view the file. And because some of those links appeared on publicly accessible HTML pages within Fiverr’s platform, Google’s crawler found them, followed them, and indexed the documents [3].
Three failures stacked on top of each other [3]:
- Public storage: Files uploaded through “private” messages were stored on unauthenticated, publicly accessible Cloudinary URLs
- No expiration: URLs never expired. A tax form shared in 2023 was still accessible in 2026
- Search engine indexing: Public HTML pages linked to these URLs, giving Google a breadcrumb trail straight to sensitive documents
As cybersecurity expert David Stuart put it, this was “a failure to understand where regulated data lives”: not a hack, not a zero-day, just an unlocked door [2].
40 Days of Silence, Then Denial
Morpheuskafka reported the vulnerability to [email protected] approximately 40 days before going public. No response. No acknowledgment. Nothing [1].
The researcher couldn’t file a CVE (Common Vulnerabilities and Exposures) because this was a configuration issue, not a software vulnerability. There was no CERT process to escalate to. The only option left was public disclosure [4].
When Fiverr finally responded, after the story hit Hacker News, Cybernews, HackRead, and Privacy Guides, the company issued a statement that privacy researchers found jaw-dropping [1]:
“This is not a cyber incident. Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers.”
Read that carefully. Fiverr’s defense is that freelancers chose to share these files. That a freelancer sending a W-9 to a client through Fiverr’s messaging system was “normal marketplace activity.” That the resulting public indexing of their Social Security Number on Google was somehow the freelancer’s fault.
Sharing a tax form with one specific client is not the same as publishing it on Google. Every freelancer who used Fiverr’s messaging system assumed those files were private. The platform’s design implied privacy. The reality delivered the opposite.
The Expired Security Certificate
Here’s the detail that makes this worse: Fiverr’s ISO 27001 information security certification had expired at the time of the exposure [4].
ISO 27001 is the international standard for information security management systems. Companies get certified to prove they follow security best practices. Clients and partners use it as a trust signal. “We’re ISO 27001 certified” is boilerplate on enterprise sales pages.
Fiverr let that certification lapse. For a company handling millions of users’ sensitive documents, that’s not a paperwork oversight: it’s a signal that security governance slipped.
How Big Is This?
Fiverr has over 4 million active buyers and hundreds of thousands of active sellers. The platform processes millions of transactions annually. Every one of those transactions could involve file exchanges through the messaging system [5].
The exact number of exposed documents is unknown: Fiverr hasn’t disclosed it, and Google’s index doesn’t show everything that was accessible via direct URL. But the exposure window could stretch back years, given that the URLs never expired.
Think about what freelancers routinely share through gig platforms:
- W-9 forms for tax reporting (SSN, address, legal name)
- Government IDs for identity verification
- Bank details for payment setup
- Client contracts with proprietary information
- API keys and credentials for technical projects
All of it treated as public content by Fiverr’s infrastructure.
The Cloud Misconfiguration Epidemic
Fiverr isn’t the first company to turn “private” uploads into public content. This pattern keeps repeating because companies treat cloud storage like a dumb file cabinet instead of a security boundary, a recurring theme in the year’s worst data breaches.
The McGraw-Hill / Salesforce breach exposed 13.5 million records through a misconfigured cloud service. The Mercor breach leaked 4TB of data including passport scans through cloud storage buckets. ShinyHunters built an entire campaign around exploiting cloud misconfigurations across 100+ companies.
The Fiverr case is different in one way: there was no attacker. No hackers. No ransomware group. No extortion. Just a company that couldn’t keep track of where sensitive data lived across its third-party infrastructure. Google’s search crawler did what it always does: indexed public content. The problem was that “public content” included your tax returns.
What Fiverr Users Should Do Right Now
- Check Google: Search
site:fiverr-res.cloudinary.comfollowed by your name, email, or identifying details. See what comes up. If you find your documents, screenshot them as evidence and request Google remove them - Monitor your credit: If you shared W-9s or tax forms through Fiverr, your SSN may be exposed. Place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). It takes five minutes each and costs nothing
- Change exposed credentials: If you ever shared API keys, passwords, or login details through Fiverr’s messaging, rotate them immediately. Assume they’re compromised
- Audit your Fiverr messages: Go through your sent messages and note what files you’ve shared. Anything sensitive needs mitigation
- Stop sharing sensitive documents through platform messaging: Use encrypted file-sharing tools like Tresorit or Proton Drive instead. Or at minimum, password-protect files before uploading
- File a complaint: If your data was exposed, file a complaint with the FTC and your state attorney general. Companies that mishandle personal data should face consequences
The Gig Economy’s Privacy Problem
Fiverr, Upwork, Freelancer.com, Toptal: every gig platform asks freelancers to hand over intimate personal data as a condition of getting paid. Tax forms. IDs. Bank details. Address verification. The platforms collect it all, store it on third-party infrastructure they don’t fully control, and call it “marketplace activity” when it leaks.
Freelancers don’t have a corporate IT department watching their back. They don’t have a security team auditing their file-sharing practices. They trust the platform to handle their data responsibly because the platform told them to upload it.
When that trust breaks, when your 1040 shows up on Google because a $2 billion company couldn’t configure a CDN properly, the freelancer absorbs all the risk. Fiverr gets to say it “wasn’t a cyber incident.”
References
- HackRead: Researchers Say Fiverr Left User Files Open to Google Search (April 2026)
- Cybersecurity Insiders: Fiverr Data Breach Exposes Sensitive User Data via Cloud (April 2026)
- Sentra: Fiverr Data Breach: Beyond Misconfigured Buckets and the Data Sprawl That Made It Inevitable (April 2026)
- Privacy Guides: Fiverr Exposes Private Information of Its Users Publicly on Google Search Results (April 16, 2026)
- PYMNTS: Fiverr Denies Report of Data Leak (April 2026)
Published: April 18, 2026