Sponsored
General News

ClarityCheck: More Than 9 Million Face Image Files Found Exposed

A 450.2GB cloud database contained photos of adults, teenagers and children, but there is no evidence that nine million unique people were affected.

Εικόνες προσώπων σε βάση δεδομένων που συνδέθηκε με την ClarityCheck
A sample representing the types of facial images found in the exposed cloud database linked to ClarityCheck.

Summary

  • 9,042,977 image files totaling 450.2GB were discovered
  • The database was linked to ClarityCheck and stored in an Amazon S3 bucket
  • The reviewed sample included photos of adults, teenagers and children
  • Nine million files do not mean nine million unique individuals
  • There is no evidence that third parties downloaded or exploited the data
  • ClarityCheck has since restricted access
  • Its current European privacy policy sets a maximum seven-day retention period for reverse-image uploads
Contents
  1. What the researcher found
  2. How the database is connected to ClarityCheck
  3. What ClarityCheck says about the data being “exposed”
  4. There is no evidence the files were stolen
  5. A second issue exposed personal information
  6. Why facial photographs create a different risk
  7. European retention policy now sets a seven-day limit
  8. What European rules say about facial images
  9. What we think
  10. Frequently asked questions

More than nine million image files, many showing the faces of adults, teenagers and children, were discovered in unsecured cloud storage linked to the people-search and reverse-lookup service ClarityCheck.

Cybersecurity researcher Jeremiah Fowler discovered a database containing 9,042,977 image files totaling 450.2GB that required no password or other form of authentication. The data was stored in an Amazon S3 bucket and included profile images, screenshots and other photographs, with folders carrying names such as “faces” and “profiles.”

The case matters because a facial photograph is not simply another file that can be replaced after an exposure. It can potentially be used for searches, matching and linking a real person to other publicly available information, while it remains unknown whether any third parties accessed or downloaded the files.

What the researcher found

According to Fowler’s report, the database was accessible online without password protection or encryption and contained exactly 9,042,977 image files totaling 450.2GB. In a limited sample he reviewed, the researcher saw images of adults, teenagers and children, including profile pictures, screenshots and photographs that appeared to have been submitted for reverse-image searches or related functions.

Fowler linked the files to US-based ClarityCheck through information in the website’s source code, which, according to his investigation, revealed the cloud storage address. It has not been confirmed whether the bucket was managed directly by ClarityCheck or by an external contractor.

A critical detail is that “nine million” does not necessarily mean nine million different people. ClarityCheck told WIRED that the files included duplicate, cropped and resized versions of the same images, meaning the actual number of unique individuals remains unknown.

How the database is connected to ClarityCheck

ClarityCheck operates as a people-search and reverse-lookup service. It offers searches using details such as names, emails, phone numbers, VINs and photographs, compiling information from public sources and other data providers.

Its reverse-image search allows a user to upload a photograph so the service can search for related appearances of the image or information online. ClarityCheck currently states in its EU and UK privacy policy that users must be at least 18 and must own the image, appear in it, or otherwise possess the necessary rights and permissions to submit it.

That does not necessarily mean every person appearing in an uploaded photograph knows that their image has been submitted to such a service. Fowler noted that some images may have originated from social media, dating profiles, screenshots or even physical photographs uploaded by third parties.

What ClarityCheck says about the data being “exposed”

The company disputed the characterization that the database was publicly exposed in the sense of being easily accessible to the general public. In a statement to WIRED, it said access required knowledge of a specific, unindexed URL that could not be discovered through normal use of the service or a general web search.

Fowler, however, says no password or authentication was required and that anyone who knew the address could access the database. The fact that a URL is not indexed by search engines does not itself constitute access control.

The database has now been restricted. According to WIRED, access was closed after the publication contacted the company in July, while ClarityCheck also said it had improved the process through which security researchers can report vulnerabilities.

There is no evidence the files were stolen

There is currently no public evidence showing that malicious third parties downloaded the database or used the photographs.

Fowler himself is careful on this point: he does not claim that third parties accessed the files or that ClarityCheck’s internal systems were compromised. His investigation documents a data exposure and the potential risks it created, not a confirmed theft of nine million photographs.

For that reason, “data exposure” is more accurate than stating as fact that the company was “hacked”: the information was available without the expected access controls, but exfiltration has not been proven.

A second issue exposed personal information

WIRED’s investigation also identified a separate misconfiguration affecting ClarityCheck APIs.

By modifying URLs, results associated with names could reveal potential email addresses, physical addresses and telephone numbers. The company said those details originated from publicly available information and licensed third-party data providers. The affected URLs were also secured following WIRED’s contact with the company.

The combination of a photograph with additional personal information is what can significantly increase the potential for abuse, ranging from fake social-media accounts and impersonation to more convincing phishing and social-engineering attempts.

PTTL recently covered another example of how an apparently ordinary photograph can become a source of personal information: research showing how holiday photos can be used for geolocation and more convincing scams.

Why facial photographs create a different risk

A leaked password can be changed. A person’s face cannot.

Fowler notes that large image collections could theoretically become more valuable as AI, face-matching and automated identification systems improve. This does not mean ClarityCheck’s exposed files were actually used to train AI systems or for surveillance; there is no such evidence in the investigation.

ClarityCheck itself states in its current European privacy policy that it does not create or maintain a proprietary facial-image index or database of biometric profiles and that images uploaded solely for reverse-image searches are not used for AI model training without separate express consent.

European retention policy now sets a seven-day limit

There is an interesting change compared with what Fowler documented during his investigation.

In his report, the researcher says ClarityCheck’s terms at the time referred to a 14-day image retention period and that he observed files with timestamps exceeding that period.

ClarityCheck’s current Privacy Policy for EU and UK users, as available on August 27, 2026, now states that reverse-image uploads, related temporary processing files and report-cache assets are retained for no longer than seven days and are then deleted from active systems within a commercially reasonable timeframe, subject to limited exceptions for security, backups and legal obligations.

What European rules say about facial images

Under the GDPR, an important legal distinction is that every ordinary photograph of a face is not automatically special-category biometric data.

The regulation defines biometric data as personal data resulting from specific technical processing relating to physical, physiological or behavioral characteristics that allow or confirm the unique identification of an individual, explicitly citing facial images as an example.

In other words, how a facial image is processed and used is critical to its legal classification.

The European Data Protection Board has repeatedly stressed that biometric information is particularly sensitive and that its misuse can lead, among other consequences, to identity fraud and impersonation.

Europe has already faced similar tensions surrounding massive collections of online images and facial-recognition technology. PTTL previously covered the French CNIL order requiring Clearview AI to delete biometric data collected from online images.

What we think

The most important detail in this case is not simply the striking figure of 9,042,977 files, but the type of material involved and the ways in which it could potentially be linked to real people.

It has not been established that nine million different individuals were affected, nor that anyone maliciously downloaded the database. Both distinctions are essential if the incident is to be reported without overstating the available evidence.

At the same time, a service that processes photographs in order to search for people needs to treat such material with a much higher level of protection than an ordinary file. The case demonstrates how quickly the value and sensitivity of a photograph can change when it is combined with reverse lookup, public information and automated search tools.

Frequently asked questions

Were photos of nine million different people exposed?

That has not been confirmed. Researchers found 9,042,977 image files, but ClarityCheck says the collection contained duplicate, cropped and resized versions of the same files. The number of unique individuals is unknown.

Is there evidence hackers downloaded the database?

No. Jeremiah Fowler says it is unknown whether any third parties accessed or downloaded the data. An internal forensic investigation would be needed to determine that.

Were photographs of children included?

Yes. Fowler says the limited sample he reviewed contained images of adults, teenagers and children.

Is the database still publicly accessible?

Not according to the available information. Access to the storage has since been restricted.

Does ClarityCheck currently keep uploaded images for 14 days?

Its current EU and UK privacy policy states a maximum retention period of seven days for reverse-image uploads and related temporary assets.

Comments

Leave a comment