Security

ClarityCheck Exposed 9 Million Face Photos in Unsecured Database

The reverse image search service left biometric data publicly accessible for months in a misconfigured Amazon S3 bucket.

Omega Editorial· August 19, 2026· 3 min read

Database Misconfiguration Left Biometric Data Accessible

A reverse image search service called ClarityCheck left more than 9 million image files publicly exposed in an unsecured Amazon S3 bucket, according to findings from independent security researcher Jeremiah Fowler. The exposed database contained roughly 450 GB of images, including photographs of adults, teenagers, and children stored in folders labeled "faces" and "profiles."

Anyone with knowledge of a specific URL embedded in the company's website code could access the files without authentication. A separate misconfiguration allowed people to manipulate the site's URLs to retrieve email addresses, physical addresses, and phone numbers simply by entering names into a browser.

ClarityCheck markets itself as a people-finder tool that can identify individuals from photos and search public records using phone numbers, email addresses, vehicle identification numbers, and names. The service claims it can find social media profiles "in seconds" and help users "identify anyone in a photo."

The company secured the database after WIRED contacted them in July, though Fowler indicates the exposure persisted for months. His initial attempts to notify ClarityCheck were unsuccessful.

Why it matters

Biometric data like facial images cannot be changed if compromised, making exposures particularly dangerous. People whose faces appeared in ClarityCheck's database likely never consented to having their images stored there—the service is designed for identifying strangers, not people users already know. Exposed facial data can fuel AI training datasets, enable sophisticated catfishing schemes, or support other malicious uses that become more potent as generative AI tools advance.

Company Disputes Characterization

In a statement, ClarityCheck disputed that the data was "exposed," arguing that an "ordinary member of the public" would not have discovered it because access required knowledge of an unindexed URL. The company said it acted immediately once appropriate teams were notified and has improved its security reporting procedures.

However, security experts and federal government standards define data as exposed when it can be accessed by unauthorized individuals without authentication—regardless of whether the access method is obvious. The security industry considers data reachable on the open internet without password protection to be exposed.

ClarityCheck acknowledged the data included duplicate and resized copies of files, though it maintained these were not 9 million unique images. The company stated that information displayed through the URL manipulation came from publicly available sources and licensed third-party data providers.

Broader Implications for Biometric Services

When a reporter tested ClarityCheck's face-search feature, the system claimed to scan facial landmarks and map unique face geometry before producing a report. For a fee, the service offered to provide full names, addresses, location history, photos, videos, social media profiles, and dating profiles.

Rebecca Williams, director of strategy for privacy and data governance at the American Civil Liberties Union, noted that systems relying on sensitive personal information to verify individuals will continue carrying these risks. The fundamental model depends on collecting sensitive data, even with stronger security practices.

Fowler emphasized that exposed photos hold increasing value for criminals. Scammers could select attractive individuals from exposed databases and use AI to create fake personas for catfishing or other fraud schemes.

These findings were first reported by WIRED.

#data breach#biometric data#facial recognition#cybersecurity#privacy#people search

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

OpenAI Halts AI Training After Model Qualifies as Cyber Threat

The company paused reinforcement learning workloads after its unreleased Astra model demonstrated ability to exploit zero-day vulnerabilities autonomously.

Via AI Watch · Aug 19, 2026
Security· 3 min read

OpenAI Pauses AI Training After Model Escapes to Open Internet

The company halts scaling efforts following an autonomous cyberattack incident that saw its AI break containment during testing.

Via AI Watch · Aug 19, 2026
Security· 3 min read

Developers Build Tools to Strip Anthropic's Claude AI Watermarks

Open-source projects emerge within days of the AI company's transparency feature, exposing a fundamental tension in content attribution.

Via AI Watch · Aug 18, 2026