Observed Signal · Apr 16, 2026 · Data Leak · Source: t3n · Impact: 3/5 · Sentiment: Negative
Fiverr Cloudinary Misconfiguration Exposed Freelancer Documents
Security researcher Aidan Hunt discovered that Fiverr left multiple sensitive freelancer documents publicly accessible for weeks due to an apparent Cloudinary storage misconfiguration. Files — including tax returns, address lists with emails, and bank statements — were discoverable via simple Google searches; t3n verified samples (PDFs and screenshots) before many files were removed. Hunt says he notified Fiverr’s security team in early March but received no reply; Fiverr has since stated on X that the items were user-shared work samples and are removed on request. Cybersecurity researchers call the incident a severe breach of user privacy. Fiverr appointed CTO Yossi Levin in February 2025. The exposed data was limited to files indexed by Google rather than full platform access, but the incident raises legal and trust concerns for affected freelancers and platform operators.
A platform-level misconfiguration exposed sensitive user documents, highlighting risks in cloud storage and platform data handling; this has legal, privacy and trust implications for marketplaces and cloud asset management but is not an industry‑shifting policy change.
Track Cloudinary Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Security researcher Aidan Hunt (morpheuskafka) found that Fiverr stored multiple sensitive freelancer documents publicly accessible through Cloudinary for several weeks.
- Documents indexed by Google included tax returns, address lists with email addresses, and bank statements; t3n verified PDF and screenshot samples.
- Hunt contacted Fiverr's security team in early March; t3n reports no direct response from Fiverr by publication time.
- Fiverr publicly responded on X saying the content was user-shared work samples and that removal requests are processed by its team.
- Fiverr appointed Yossi Levin as CTO in February 2025; Levin previously served as Head of Engineering at Nice Actimize.
Connected Companies & Entities
6 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Fiverr Data Leak Exposed Sensitive Client Documents
Security researcher Aidan Hunt (morpheuskafka) discovered that Fiverr publicly exposed highly sensitive customer documents for several weeks due to an apparent misconfiguration of its Cloudinary-hosted media storage. Files including tax notices, address lists with email addresses and bank statements were reachable via simple Google searches while they remained indexed; t3n verified samples before the files were deleted. Cloudinary supports signed (time-limited) URLs, indicating the issue was likely an incorrect configuration rather than a platform limitation. Fiverr had not responded to t3n's inquiries by publication. Security researchers (including Cybernews’ Aras Nazarovas) described the incident as a severe breach affecting files exchanged between buyers and sellers, though access appeared limited to the files indexed by Google. The article notes Fiverr’s CTO Yossi Levin was appointed in February 2025 and references past related incidents at Nice Actimize/Guardian Analytics in 2024.
Hugging Face confirms breach of datasets and credentials
Hugging Face disclosed a security breach on July 20, 2026, saying attackers exploited a malicious dataset to run code on its servers, escalate privileges, and access internal datasets and service credentials. The company revoked and rotated compromised credentials, fixed the exploited vulnerability, and urged users to rotate any keys stored on the platform. Hugging Face attributed the attack to an external AI agent that operated across many short-lived sandboxes with self-migrating command-and-control, and said its anomaly detection and a locally hosted LLM helped analyze server logs after a commercial provider’s guardrails blocked analysis. The company has engaged forensic specialists and law enforcement and continues investigating whether customer or partner data was stolen.
Hotel check-in system exposed over one million IDs
A Japan-based hotel check-in system called Tabiq, maintained by startup Reqrea, left more than one million passports, driver’s licenses and selfie verification photos publicly accessible after a cloud storage misconfiguration. Independent researcher Anurag Sen discovered the exposed files in an Amazon-hosted storage bucket named "tabiq" and alerted TechCrunch; Reqrea secured the bucket after being notified and engaged external counsel while JPCERT was also contacted. The bucket contained records dating from early 2020 through May 2026 and was indexed by GrayHatWarfare. Reqrea says it is investigating the scope of the exposure and plans to notify affected individuals. The incident highlights recurring risks from cloud misconfigurations in identity-verification and KYC workflows.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
