Fiverr Rejects Data-Leak Claims, Denies Exposure of User Invoices and Tax Documents
Fiverr is a digital services platform connecting buyers with freelancers, who may exchange work products, contracts and identity documents during transactions. Cybernews cited an anonymous researcher known as morpheuskafka, who alleged that a publicly accessible Cloudinary storage repository apparently belonging to Fiverr made invoices, tax returns, driver's licenses, passwords and API keys searchable, raising concerns about personal data and account security.
PYMNTS reported on April 15, 2026, that Fiverr responded to Cybernews on X and denied the matter constituted a cybersecurity incident. Fiverr said the material consisted of work samples uploaded by buyers and sellers under agreements and with consent, that the platform had not proactively made private data public, and that it would process deletion requests. Cybernews said Google had indexed some files. The number of people affected, the value of any losses and Cloudinary's response were not disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.