Reverse-lookup service exposed millions of photos of people’s faces
People-search service ClarityCheck left more than nine million images, including photographs of people's faces, publicly accessible online despite telling users their reverse image searches were "private and secure." Security researcher Jeremiah Fowler discovered the unsecured database, along with a separate misconfiguration exposing users' email addresses and phone numbers, raising concerns about how such "people-finder" tools handle sensitive biometric data that individuals often have no knowledge is being stored.
The exposed database, held in an unsecured Amazon S3 bucket, contained roughly 450 GB of images in folders labelled "faces" and "profiles", including photos of adults, teenagers and children, accessible via a URL embedded in the company's public website code. ClarityCheck secured the database only after being contacted by WIRED in July, though Fowler says it had likely been exposed for months and his earlier attempts to alert the company failed. ClarityCheck disputed that the data was genuinely "exposed", arguing that access required knowledge of a specific, unindexed URL not discoverable through ordinary searches, though security experts and the US government generally classify unauthenticated, internet-reachable data as exposed regardless of whether it was actively found.
- ClarityCheck exposed over 9 million face photos in an unsecured database
- Researcher also found leaked user emails and phone numbers
- Company disputes the data was truly "publicly exposed"