Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

ClarityCheck's Private and Secure Reverse Image Search Service Exposed Millions of People's Faces


ClarityCheck's private and secure reverse image search service has been exposed to contain over 9 million image files, including photographs of people's faces, that were left publicly accessible. The incident highlights the importance of robust security measures and the need for companies to prioritize data protection.

  • ClarityCheck's reverse image search service left over 9 million image files, including people's faces, publicly accessible due to a misconfigured Amazon S3 bucket.
  • The exposed database, containing 450 GB of images, was discovered by independent security researcher Jeremiah Fowler and included duplicate, cropped, and resized copies of the same files.
  • The images were stored in folders that could be accessed by anyone online, posing a risk to users' privacy and security.
  • Security experts emphasize the importance of robust security measures and the need for companies to prioritize data protection to prevent similar incidents.
  • The incident highlights the risks associated with data breaches and the potential for scammers and cybercriminals to exploit exposed data.



  • In a stunning revelation, a reverse image search service operated by ClarityCheck, a people-search tool, has been exposed to contain over 9 million image files, including photographs of people's faces, that were left publicly accessible. The service, which claims to be "private and secure," left its massive database of images exposed due to a misconfiguration in its Amazon S3 bucket, which was accessible through a publicly available URL.

    The exposed database, which contained roughly 450 GB of images, was discovered by independent security researcher Jeremiah Fowler, who initially attempted to flag the issue to ClarityCheck but was unsuccessful. The images in the database included what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children, all stored in folders named "faces" and "profiles" that could be accessed by anyone online.

    ClarityCheck's face-search feature allows users to upload an image and receive a report about where that image may appear online and who may be shown in the photo. However, the company's claims of privacy and security were breached when the images were left publicly accessible. The exposed database, which included duplicate, cropped, and resized copies of the same files, as well as non-image data, was not only a security risk but also a potential tool for scammers and cybercriminals.

    According to security industry experts, the exposed data is a prime example of the risks associated with data breaches and the importance of robust security measures. "Exposure is the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access," said Mark Beare, head of consumer products at the security company Malwarebytes. "A publicly reachable database backup, a misconfigured storage bucket, or credentials sitting in a system that a researcher can reach are all exposures."

    ClarityCheck's spokesperson disputed the characterization of the data as "exposed," claiming that an "ordinary member of the public" would not have accessed the database. However, security researcher Jeremiah Fowler emphasized that the exposed data, including photos, are more valuable than ever to scammers and cybercriminals. "If you're trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public," Fowler said.

    The incident highlights the importance of robust security measures and the need for companies to prioritize data protection. "Systems that rely on highly sensitive personal information to verify individuals will continue to carry these risks, even with stronger data minimization and security practices, because the model itself depends on collecting sensitive data," said Rebecca Williams, director of strategy for privacy and data governance at the American Civil Liberties Union.

    In response to the incident, ClarityCheck has secured the giant image database and improved its security reporting procedures to help other researchers contact the company in the future. However, the incident serves as a reminder that data breaches and security vulnerabilities are a constant threat, and companies must remain vigilant in protecting sensitive information.

    The incident also raises questions about the ethics of reverse image search services and the potential risks associated with collecting and analyzing sensitive personal data. "Let's say I was in a criminal outfit and I was catfishing people, and I scroll through all these pictures and I pick out 20 of the most attractive people and then I just use their image and AI and I create a persona," Fowler said.

    In conclusion, the exposure of ClarityCheck's reverse image search service highlights the importance of robust security measures and the need for companies to prioritize data protection. The incident serves as a reminder that data breaches and security vulnerabilities are a constant threat, and companies must remain vigilant in protecting sensitive information.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/ClarityChecks-Private-and-Secure-Reverse-Image-Search-Service-Exposed-Millions-of-Peoples-Faces-ehn.shtml

  • https://www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/


  • Published: Wed Aug 19 06:35:13 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us