ClarityCheck Exposed 9M+ Face Photos in Unsecured Database
Original: Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
Why This Matters
The incident highlights compounding risks when people-finder services mishandle sensitive biometric and contact data at scale.
People-search tool ClarityCheck left over 9 million image files—including face photos of adults, children, and teens—exposed in an unsecured Amazon S3 bucket, totaling ~450 GB. A second misconfiguration also exposed users' email addresses and phone numbers, per researcher Jeremiah Fowler.
Independent security researcher Jeremiah Fowler discovered that ClarityCheck, a people-finder website that markets its reverse image search as "private and secure," had left approximately 450 GB of image data—over 9 million files—publicly accessible in an unsecured Amazon S3 bucket. The files were stored in folders labeled "faces" and "profiles" and included profile images, screenshots, and photographs of adults, teenagers, and children. The bucket's URL was embedded in the company's publicly available website code, making it accessible to anyone who knew the address. A separate misconfiguration also exposed users' email addresses and phone numbers.
Fowler flagged the issue to ClarityCheck but received no initial response. WIRED contacted the company in July 2026, after which ClarityCheck secured the database. Fowler warned the data appeared exposed for months and noted particular risks around biometric data: face images are immutable, and the people photographed may have had no awareness their image was held by the service. He also raised concern that AI bots could have crawled and harvested the images for training datasets.
ClarityCheck disputed the characterization of the data as "publicly exposed," arguing that access required knowledge of a specific, unindexed URL not discoverable through ordinary use of its platform.