ClarityCheck, a people-search tool, left a database containing over 9 million image files, including many faces, publicly exposed. A separate misconfiguration also exposed users' email addresses and phone numbers.

The exposure of millions of face images and personal contact details by a people-search service highlights significant risks associated with sensitive biometric data and the broader implications for online privacy and security, especially as AI capabilities advance.
The people-search service ClarityCheck left a database containing over 9 million image files, including many photographs of people's faces, publicly exposed. Independent security researcher Jeremiah Fowler discovered the unsecured Amazon S3 bucket, which contained approximately 450 GB of images, including profile pictures and screenshots of adults, teenagers, and children. The files were accessible via URLs embedded in the company's publicly available website code.
In addition to the image exposure, a separate misconfiguration allowed for the exposure of users' email addresses and phone numbers. Fowler noted that the data appeared to have been exposed for months, and his initial attempts to alert ClarityCheck were unsuccessful. The company eventually secured the database and APIs after being contacted by WIRED in July.
ClarityCheck disputed the characterization of the data as 'publicly exposed,' arguing that access required knowledge of a specific, unindexed URL and that the data consisted of duplicate files rather than 9 million unique images. However, security experts define data as exposed if it is accessible to unauthorized individuals on the open internet without authentication.
The service's face-search feature allows users to upload an image to identify individuals and find associated online information, including social media profiles, addresses, and public appearances. Experts warn that exposed biometric data like face images is particularly valuable to scammers and cybercriminals.