ClarityCheck Data Breach Exposes Millions of Facial Images and Personal Details
Security researcher Jeremiah Fowler identified the misconfiguration, which stored 450GB of images including photos of children. ClarityCheck disputes the term "exposed" but has secured the database following contact from WIRED.

People-search platform ClarityCheck has left a database containing more than 9 million image files publicly accessible due to a misconfigured Amazon S3 bucket. The exposed data includes facial photographs, profile images, and screenshots of adults, teenagers, and children, alongside personal details such as email addresses and phone numbers.
Independent security researcher Jeremiah Fowler identified the vulnerability, which allowed unauthenticated access to folders named “faces” and “profiles” via a URL embedded in the company’s public website code. The database contained approximately 450GB of data. Additionally, API misconfigurations enabled users to retrieve personal information, including physical addresses and contact details, by manipulating website URLs with specific names.
ClarityCheck, which markets itself as a tool to identify individuals using photos, phone numbers, and public records, disputed the characterisation of the incident as a data exposure. A company spokesperson argued that the storage location was unindexed and not discoverable through ordinary web searches, stating that access required knowledge of a specific URL. The company also noted that the data included duplicate, cropped, and resized copies of files, rather than 9 million unique images.
Despite the company’s stance, security experts define data exposure as any instance where sensitive information is left accessible on the open internet without authentication. Mark Beare of Malwarebytes stated that a misconfigured storage bucket constitutes an exposure regardless of whether it was actively misused. The American Civil Liberties Union’s Rebecca Williams highlighted that systems relying on sensitive biometric data for verification carry inherent risks, even with improved security practices.
The exposure poses significant risks for identity theft and artificial intelligence training, particularly given the presence of images of children. Fowler warned that cybercriminals could utilise the data for catfishing or creating AI personas. ClarityCheck has since secured the database and improved its security reporting procedures after being contacted by WIRED in July.

