“Your reverse image search is private and secure.” That’s what ClarityCheck told every user. A researcher found 9 million of their faces sitting in an unprotected cloud folder labelled, plainly, “faces.”
Security researcher Jeremiah Fowler found an unsecured database belonging to ClarityCheck, a people-search tool that lets anyone upload a photo to identify the person in it. The exposed database contained 9,042,977 image files — roughly 450.2 GB — including profile photos, screenshots, and scanned photographs of adults, teenagers, and children. All of it sat in a folder labelled “faces,” accessible through a URL embedded in ClarityCheck’s own public website code, with no password required. A second misconfiguration exposed users’ email addresses and phone numbers.
What’s Happening & Why It Matters
What ClarityCheck Does — and Told Users

ClarityCheck markets itself around identification: “Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds.” Its own website carries a specific promise to anyone uploading a photo: “Your reverse image search is private and secure.” Fowler’s findings contradict that claim in the most literal way possible — the database sat unprotected in an Amazon AWS S3 storage bucket, requiring no authentication whatsoever to access.
The company requires users to confirm they have permission to upload a given photo before running a search. Fowler told WIRED he was “extremely sceptical” of that safeguard, noting the service is designed for identifying other people — and people don’t need to identify themselves or those they already know. That’s the structural weakness underneath the whole product: a tool built to identify strangers has no reliable way to confirm the uploader has that stranger’s consent.
Worse Than a Typical Leak
Most data breaches expose information people at least chose to hand over — an email signup, a purchase, an account registration. This is different. Fowler noted many of the exposed images appeared to originate from private social media profiles, dating app accounts, and screenshots — meaning a meaningful share of the roughly 9 million faces in the database belong to people who never used ClarityCheck at all. Someone else uploaded their photo to search for them.

Access matters legally and ethically. A person who signs up for a service and gets breached at least made a choice, however informed. A person whose face ends up in an unsecured database because someone else uploaded their photo to identify them made no choice whatsoever. Security Magazine flagged a specific and alarming concern tied to the children’s images in the dataset — recent incidents have shown cybercriminals generating AI child abuse imagery of real students to extort schools. Fowler was careful to note there’s no evidence any malicious actor accessed the particular database before it was secured — that risk is hypothetical, not confirmed.
ClarityCheck’s Response
ClarityCheck pushed back on WIRED’s characterisation that the database was “public.” However, the company hasn’t disputed the core finding — that a URL embedded in its own website code led to more than 9 million unprotected image files. The company hasn’t detailed a specific remediation timeline or confirmed how long the exposure lasted. However, multiple outlets reported the database had been accessible for “several months” before Fowler discovered it.

TF Summary: What’s Next
ClarityCheck has not confirmed a specific date the exposed database was secured or how many affected individuals it plans to notify. No regulatory investigation has been announced as of this writing. Fowler continues his pattern of identifying and disclosing exposed cloud databases through ExpressVPN’s security research arm, where he first published his findings.
MY FORECAST: Expect the incident to accelerate regulatory scrutiny of the people-search and reverse-image-lookup industry, a sector that’s operated with minimal oversight despite handling the kind of sensitive biometric data GDPR and comparable US state privacy laws were written to protect. The children’s-images detail is the one most likely to trigger formal action — a facial database containing minors’ photos, exposed without their knowledge or consent, is the fact pattern that draws attorneys general’s attention fastest. Watch whether ClarityCheck faces a class action similar to the 2024 National Public Data breach, given the comparable scale and the added complication that many affected people never had a relationship with the company at all.
Related Stories
- British Councils Turn to AI to Bridge a £4 Billion Funding Gap
- Flock Admits It Should Have Stopped Police From Abusing Its Cameras
- A Judge Just Halted Paramount’s $111 Billion Warner Bros. Discovery Acquisition

