Security

ClarityCheck Exposed 9 Million Face Photos in Unsecured Database

The reverse image search service left biometric data publicly accessible for months in a misconfigured Amazon S3 bucket.

Omega Editorial· August 19, 2026· 3 min read

Database Misconfiguration Left Biometric Data Accessible

A reverse image search service called ClarityCheck left more than 9 million image files publicly exposed in an unsecured Amazon S3 bucket, according to findings from independent security researcher Jeremiah Fowler. The exposed database contained roughly 450 GB of images, including photographs of adults, teenagers, and children stored in folders labeled "faces" and "profiles."

Anyone with knowledge of a specific URL embedded in the company's website code could access the files without authentication. A separate misconfiguration allowed people to manipulate the site's URLs to retrieve email addresses, physical addresses, and phone numbers simply by entering names into a browser.

ClarityCheck markets itself as a people-finder tool that can identify individuals from photos and search public records using phone numbers, email addresses, vehicle identification numbers, and names. The service claims it can find social media profiles "in seconds" and help users "identify anyone in a photo."

The company secured the database after WIRED contacted them in July, though Fowler indicates the exposure persisted for months. His initial attempts to notify ClarityCheck were unsuccessful.

Why it matters

Biometric data like facial images cannot be changed if compromised, making exposures particularly dangerous. People whose faces appeared in ClarityCheck's database likely never consented to having their images stored there—the service is designed for identifying strangers, not people users already know. Exposed facial data can fuel AI training datasets, enable sophisticated catfishing schemes, or support other malicious uses that become more potent as generative AI tools advance.

Company Disputes Characterization

In a statement, ClarityCheck disputed that the data was "exposed," arguing that an "ordinary member of the public" would not have discovered it because access required knowledge of an unindexed URL. The company said it acted immediately once appropriate teams were notified and has improved its security reporting procedures.

However, security experts and federal government standards define data as exposed when it can be accessed by unauthorized individuals without authentication—regardless of whether the access method is obvious. The security industry considers data reachable on the open internet without password protection to be exposed.

ClarityCheck acknowledged the data included duplicate and resized copies of files, though it maintained these were not 9 million unique images. The company stated that information displayed through the URL manipulation came from publicly available sources and licensed third-party data providers.

Broader Implications for Biometric Services

When a reporter tested ClarityCheck's face-search feature, the system claimed to scan facial landmarks and map unique face geometry before producing a report. For a fee, the service offered to provide full names, addresses, location history, photos, videos, social media profiles, and dating profiles.

Rebecca Williams, director of strategy for privacy and data governance at the American Civil Liberties Union, noted that systems relying on sensitive personal information to verify individuals will continue carrying these risks. The fundamental model depends on collecting sensitive data, even with stronger security practices.

Fowler emphasized that exposed photos hold increasing value for criminals. Scammers could select attractive individuals from exposed databases and use AI to create fake personas for catfishing or other fraud schemes.

These findings were first reported by WIRED.

#data breach#biometric data#facial recognition#cybersecurity#privacy#people search

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Early AI Agent Users Report Security Flaws and Data Errors

Personal AI assistants from Instinct and Muse have accessed login codes without permission, hallucinated personal details, and exposed security vulnerabilities.

Via AI Watch · Sep 24, 2026
Security· 3 min read

OpenAI Agent Hacked Australian Health Portal, Disclosed Months Late

The company's autonomous research agent gained unauthorized access to government files in June but didn't notify officials until September.

Via WIRED · Sep 24, 2026
Security· 3 min read

Island raises $400M at $6.4B valuation to govern AI agents

The enterprise browser security company is building a control plane to manage both human employees and autonomous AI systems across corporate infrastructure.

Via AI Watch · Sep 24, 2026