Skip to content
Data breachResolved

ClarityCheck facial-image data exposure

Security researcher Jeremiah Fowler found that ClarityCheck, a US-registered face-search and reverse-lookup service, had left roughly 450 GB of images — more than 9 million files, including photos of children — in an unsecured, publicly accessible Amazon S3 bucket, alongside a second database of emails and phone numbers.

Victim
ClarityCheck
records
9.0M

On 20 August 2026, security researcher Jeremiah Fowler publicly reported that ClarityCheck — a US-registered face-search and reverse-lookup service that marketed itself as "private and secure" — had left an unsecured trove of images in a publicly accessible Amazon S3 bucket. The exposed store held roughly 450 GB of images, comprising more than 9 million image files, including photographs of adults, teenagers and children.

The images sat in an S3 bucket whose contents could be reached by anyone online through a URL that appeared in the company's own publicly available website code, with files organized in folders named "faces" and "profiles." A second misconfigured database additionally exposed email addresses and phone numbers. No attacker or ransom was involved — this was a misconfiguration that left sensitive biometric-adjacent data open to the public internet.

What happened

According to Fowler, he spent months attempting to notify ClarityCheck about both the exposed image bucket and the second database, and received no response until a journalist intervened; the company finally locked down access following that inquiry in July. The data is secured now, but Fowler noted it had reportedly been exposed for months, and it is not possible to confirm whether any malicious actors accessed it during that window.

Because the service is a reverse face-search tool, the exposed images are precisely the kind of data that enables identification and tracking of individuals from a single photo — a privacy harm distinct from, and in some ways graver than, a conventional credential leak. The presence of images of minors sharpened the concern.

Impact

  • Roughly 450 GB of images — more than 9 million files, including photos of children — were left in an unsecured, publicly accessible S3 bucket.
  • A second misconfigured database exposed email addresses and phone numbers.
  • The data was reportedly exposed for months; access was secured only after a journalist's inquiry, and it is unknown whether malicious actors accessed it.

Why it matters

The ClarityCheck exposure is a stark reminder that cloud misconfiguration remains one of the most common and consequential causes of sensitive-data leaks — no exploit required, just a bucket left open. When the data in question is facial imagery tied to a reverse-lookup service, the privacy stakes are especially high: such images can be used to identify and profile people who never consented to being in the database. The case also underscores the value of coordinated vulnerability disclosure and the frequency with which researchers are ignored until press attention forces a response.

Timeline

  1. Researcher Jeremiah Fowler repeatedly attempts to alert ClarityCheck to the exposed data, receiving no response.

  2. Access is finally locked down after a journalist's inquiry to the company.

  3. The exposure is publicly reported, detailing roughly 450 GB and more than 9 million image files left in an unsecured S3 bucket.

Sources

  1. malwarebytes.comhttps://www.malwarebytes.com/blog/privacy/2026/08/9-million-images-of-peoples-faces-exposed-by-reverse-lookup-service
  2. tech.yahoo.comhttps://tech.yahoo.com/cybersecurity/articles/claritycheck-called-face-search-private-173040872.html
  3. yro.slashdot.orghttps://yro.slashdot.org/story/26/08/20/173219/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces

Related incidents