All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

People-search service ClarityCheck exposed millions of face images

Created at 20 Aug · 1:41 PM1 source↑ Market-relevant
IN SHORT

ClarityCheck, a people-search tool, left a database containing over 9 million image files, including many faces, publicly exposed. A separate misconfiguration also exposed users' email addresses and phone numbers.

Key Numbers

9M+image files exposed
450 GBdatabase size

Who's Involved

ClarityCheck
people-search tool that exposed user data
Jeremiah Fowler
independent security researcher who discovered the exposure
WIRED
publication that contacted the company about the breach
Rebecca Williams
director of strategy for privacy and data governance at the American Civil Liberties Union
Mark Beare
head of consumer products at Malwarebytes
People-search service ClarityCheck exposed millions of face images

↳ Why This Matters

The exposure of millions of face images and personal contact details by a people-search service highlights significant risks associated with sensitive biometric data and the broader implications for online privacy and security, especially as AI capabilities advance.

Key facts

  • ClarityCheck, a people-search tool, exposed a database with over 9 million image files.
  • The exposed data included photographs of adults, teenagers, and children, with folders named 'faces' and 'profiles'.
  • The images were stored in an unsecured Amazon S3 bucket, accessible via a URL in the company's website code.
  • A separate misconfiguration exposed users' email addresses and phone numbers.
  • ClarityCheck secured the database and APIs after being contacted by security researcher Jeremiah Fowler and WIRED.
  • The company disputed the term 'publicly exposed,' arguing access required knowledge of a specific URL.

The people-search service ClarityCheck left a database containing over 9 million image files, including many photographs of people's faces, publicly exposed. Independent security researcher Jeremiah Fowler discovered the unsecured Amazon S3 bucket, which contained approximately 450 GB of images, including profile pictures and screenshots of adults, teenagers, and children. The files were accessible via URLs embedded in the company's publicly available website code.

In addition to the image exposure, a separate misconfiguration allowed for the exposure of users' email addresses and phone numbers. Fowler noted that the data appeared to have been exposed for months, and his initial attempts to alert ClarityCheck were unsuccessful. The company eventually secured the database and APIs after being contacted by WIRED in July.

ClarityCheck disputed the characterization of the data as 'publicly exposed,' arguing that access required knowledge of a specific, unindexed URL and that the data consisted of duplicate files rather than 9 million unique images. However, security experts define data as exposed if it is accessible to unauthorized individuals on the open internet without authentication.

The service's face-search feature allows users to upload an image to identify individuals and find associated online information, including social media profiles, addresses, and public appearances. Experts warn that exposed biometric data like face images is particularly valuable to scammers and cybercriminals.

Frequently asked questions

ClarityCheck is a people-search tool that claims to identify individuals using various data points, including photos, phone numbers, email addresses, and names.

Over 9 million image files, including photographs of people's faces, and separately, users' email addresses and phone numbers were exposed.

The images were stored in an unsecured Amazon S3 bucket, and personal contact information was exposed through misconfigured APIs.

ClarityCheck stated they acted immediately to restrict access once alerted and disputed the term 'publicly exposed,' arguing access required specific knowledge of an unindexed URL.

What Happens Next

01ClarityCheck has improved its security reporting procedures for future researcher contact.

How It Developed

ClarityCheck's database containing over 9 million image files was left publicly exposed.
A second misconfiguration exposed people's email addresses and phone numbers.
Security researcher Jeremiah Fowler flagged the exposed data to ClarityCheck.
ClarityCheck secured the image database after being contacted by WIRED.
ClarityCheck disputed the characterization of the data as 'publicly exposed,' stating access required a specific, unindexed URL.
ClarityCheck stated the exposed data included duplicate files, not 9 million unique images.
The company also misconfigured APIs, allowing manipulation of URLs to reveal personal data.
ClarityCheck secured the URLs after WIRED contacted the company.

Sources

T1
Reverse-lookup service exposed millions of photos of people’s facesArs Technica

Related Stories

Canvas data breach impacts over 153,000 students, staff
20 Aug · 7:40 AM
Alation confirms cyberattack on data software platform
20 Aug · 1:16 PM
Flock Safety's New AI Tool Can Track Drivers Using Movement Patterns
20 Aug · 11:36 AM
Meta ran ads for AI porn tool targeting female politicians
19 Aug · 3:51 PM
Grok LLM Exfiltrates User Data Via Encrypted Instructions
20 Aug · 1:06 PM