ClarityCheck Exposes Over 9 Million Facial Images Due to Security Misconfiguration

Here's what it means for you.
Your personal data could be at risk due to mismanaged cloud storage practices.
Why it matters
The exposure of biometric data raises significant concerns about identity theft and privacy in an increasingly digital world.
What happened (in 30 seconds)
- On August 19, 2026, a security researcher revealed that ClarityCheck had left over 9 million facial photographs publicly accessible in an unsecured Amazon S3 bucket.
- The exposure included not only images but also a separate API flaw that allowed access to personal contact details through manipulated URLs.
- ClarityCheck secured the data after being notified by WIRED in July 2026, but disputes the characterization of the exposure as a large-scale public breach.
The context you actually need
- People-finder services like ClarityCheck aggregate public records and user-uploaded images, making them vulnerable to data misconfigurations.
- Cloud storage is often used for temporary processing of images, which can lead to accidental exposures of sensitive data.
- Biometric data breaches are becoming more common, raising alarms about the potential for identity theft and misuse in various sectors.
What's really happening
The ClarityCheck incident highlights a critical vulnerability in the management of biometric data by people-search services. With the rise of automated data collection and analysis tools, companies are increasingly relying on cloud storage solutions to handle vast amounts of user-generated content. This reliance creates opportunities for misconfigurations, as seen in this case where an unsecured Amazon S3 bucket was left accessible to the public.
Jeremiah Fowler, the independent researcher who discovered the breach, found that the exposed database contained approximately 9,042,977 image files, totaling 450.2 GB. These files were stored in folders labeled 'faces' and 'profiles,' and included a mix of profile photographs, screenshots, and scans of individuals of all ages. The fact that the bucket URL was embedded in ClarityCheck's public website source code underscores a lack of basic security protocols.
The parallel API flaw allowed name-based queries to return associated contact details, further compounding the risk. ClarityCheck initially failed to address Fowler's alerts, only securing the data after WIRED's intervention. The company has since claimed that the data consisted of duplicates and temporary copies, and that the URL was unindexed, which they argue mitigated the risk of exposure. However, privacy experts have raised concerns about the implications of such breaches, particularly regarding identity theft, catfishing, and the potential for misuse in AI training.
As biometric data becomes increasingly integrated into various applications—from security systems to social media—this incident serves as a cautionary tale. The absence of confirmed malicious access does not diminish the risks posed by such exposures. The incident has not yet prompted regulatory actions or significant market shifts, but it has sparked discussions about the need for stricter data protection measures in the industry.
Who feels it first (and how)
- Consumers: Individuals whose images and personal data may be exposed face risks of identity theft and privacy violations.
- Privacy Advocates: Experts and organizations focused on data protection will scrutinize ClarityCheck's practices and push for stronger regulations.
- Tech Companies: Other firms in the data aggregation space may face increased scrutiny and pressure to enhance their security measures.
What to watch next
- Regulatory Changes: Watch for potential new regulations aimed at protecting biometric data, which could reshape industry standards.
- Security Protocols: Monitor how ClarityCheck and similar companies improve their security measures in response to this incident.
- Public Awareness: Increased consumer awareness about data privacy may lead to greater demand for transparency and accountability from tech companies.
Over 9 million facial photographs were exposed due to misconfigured cloud storage.
Other companies may face similar scrutiny and pressure to improve data security practices.
The long-term impact on ClarityCheck's reputation and business operations remains to be seen.
Frequently Asked Questions
- Why it matters?
- The exposure of biometric data raises significant concerns about identity theft and privacy in an increasingly digital world.
- What happened (in 30 seconds)?
- On August 19, 2026, a security researcher revealed that ClarityCheck had left over 9 million facial photographs publicly accessible in an unsecured Amazon S3 bucket. The exposure included not only images but also a separate API flaw that allowed access to personal contact details through manipulated URLs. ClarityCheck secured the data after being notified by WIRED in July 2026, but disputes the characterization of the exposure as a large-scale public breach.
- What's really happening?
- The ClarityCheck incident highlights a critical vulnerability in the management of biometric data by people-search services. With the rise of automated data collection and analysis tools, companies are increasingly relying on cloud storage solutions to handle vast amounts of user-generated content. This reliance creates opportunities for misconfigurations, as seen in this case where an unsecured Amazon S3 bucket was left accessible to the public. Jeremiah Fowler, the independent researcher who
- Who feels it first (and how)?
- Consumers: Individuals whose images and personal data may be exposed face risks of identity theft and privacy violations. Privacy Advocates: Experts and organizations focused on data protection will scrutinize ClarityCheck's practices and push for stronger regulations. Tech Companies: Other firms in the data aggregation space may face increased scrutiny and pressure to enhance their security measures.
- What to watch next?
- Regulatory Changes: Watch for potential new regulations aimed at protecting biometric data, which could reshape industry standards. Security Protocols: Monitor how ClarityCheck and similar companies improve their security measures in response to this incident. Public Awareness: Increased consumer awareness about data privacy may lead to greater demand for transparency and accountability from tech companies.
In-depth reporting on tech, policy, and science including AI.
"Respected analysis for technically savvy readers, including AI topics."
— A47 Editor
Reverse-lookup service exposed millions of photos of people’s faces
ClarityCheck, a reverse image search and identity verification service, has been found to have exposed a database containing over 9 million image files, leading to significant privacy concerns. This incident highlights vulnerabilities in data securit...
In-depth coverage of hardware, software, science, and policy.
"Ars Technica provides expert technology news, hardware reviews, and analysis for a technically savvy audience."
— A47 Editor
Reverse-lookup service exposed millions of photos of people’s faces
ClarityCheck, a reverse image search and identity verification service, has been found to have exposed a database containing over 9 million image files, leading to significant privacy concerns. This incident highlights vulnerabilities in data securit...
Consumer tech news, reviews, and buying guides for gadgets and electronics.
"TechRadar is known for comprehensive buying advice, hardware reviews, and consumer tech news targeted at mainstream audiences."
— A47 Editor
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
ClarityCheck, a reverse image search and identity verification service, has experienced a significant data breach, resulting in the exposure of over 9 million facial recognition images. This incident has raised serious privacy concerns and prompted t...
Emerging technologies, digital transformation, IT, and cultural impact of tech.
"WIRED covers the intersection of technology, culture, and politics with a progressive, forward-looking editorial stance."
— A47 Editor
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
ClarityCheck, a people-search tool, has faced significant backlash after its reverse image search service was found to have exposed a database containing over 9 million image files, raising serious privacy concerns.